Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.057 exploits
GitHub PoC
Disables AJP connectors to remediate CVE-2020-1938!
CVE-2020-1938CRITICALbajo ataque17 jul 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
Exploit-DB
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
CVE-2020-15600webappsphp17 jul 2020
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
23RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALbajo ataque16 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC18
Denial of Service PoC for CVE-2020-1350 (SIGRed)
CVE-2020-1350CRITICALbajo ataque16 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC1
Environment for CVE_2019_17571
CVE-2019-17571CRITICAL16 jul 2020
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RIESGO
abrir
Exploit-DB
Zyxel Armor X1 WAP6806 - Directory Traversal
CVE-2020-14461webappshardware15 jul 2020
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RIESGO
abrir
GitHub PoC225
PoC for CVE-2020-6287, CVE-2020-6286 (SAP RECON vulnerability)
CVE-2020-6287CRITICALbajo ataque15 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
GitHub PoC237
A denial-of-service proof-of-concept for CVE-2020-1350
CVE-2020-1350CRITICALbajo ataque15 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC
Windows registry mitigation response to CVE-2020-1350
CVE-2020-1350CRITICALbajo ataque15 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC9
Detection of attempts to exploit Microsoft Windows DNS server via CVE-2020-1350 (AKA SIGRed)
CVE-2020-1350CRITICALbajo ataque15 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC15
This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service
CVE-2020-1350CRITICALbajo ataque15 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC2
ctlyz123/CVE-2020-8193
CVE-2020-8193MEDIUMbajo ataque15 jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALbajo ataque15 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-895815 jul 2020
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-6286MEDIUM15 jul 2020
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuratio
38RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-6287CRITICALbajo ataque15 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
Exploit-DB
SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin)
CVE-2020-15046webappshardware15 jul 2020
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to
23RIESGO
abrir
GitHub PoC7
Fake exploit tool, designed to rickroll users attempting to actually exploit.
CVE-2020-1350CRITICALbajo ataque14 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
Exploit-DB
Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 - Remote Code Execution (Metasploit)
CVE-2020-8605webappsmultiple14 jul 2020
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitr
60RIESGO
abrir
GitHub PoC4
mr-r3b00t/CVE-2020-1350
CVE-2020-1350CRITICALbajo ataque14 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
Exploit-DB
BSA Radar 1.6.7234.24750 - Local File Inclusion
CVE-2020-14946webappsmultiple14 jul 2020
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and e
23RIESGO
abrir
GitHub PoC279
HoneyPoC: Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server 2000 up to Windows Server 2019.
CVE-2020-1350CRITICALbajo ataque14 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
Metasploit600
Apache Airflow 1.10.10 - Example DAG Remote Code Execution
CVE-2020-11978HIGHbajo ataque14 jul 2020
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RIESGO
abrir
Metasploit300
SAP Unauthenticated WebService User Creation
CVE-2020-6287CRITICALbajo ataque14 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
Metasploit600
SharePoint DataSet / DataTable Deserialization
CVE-2020-1147HIGHbajo ataque14 jul 2020
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RIESGO
abrir
Metasploit600
Apache Airflow 1.10.10 - Example DAG Remote Code Execution
CVE-2020-13927CRITICALbajo ataque14 jul 2020
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-18988HIGHbajo ataque13 jul 2020
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RIESGO
abrir
Metasploit600
Apache OFBiz XML-RPC Java Deserialization
CVE-2023-4907013 jul 2020
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-11043HIGHbajo ataqueransomware13 jul 2020
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Metasploit600
Apache OFBiz XML-RPC Java Deserialization
CVE-2020-949613 jul 2020
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
anteriorpágina 760 / 2636siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.