Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
VulnCheck XDB
remote-with-credentials
CVE-2018-7602CRITICALbajo ataqueransomware25 jun 2020
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
Exploit-DB
mySCADA myPRO 7 - Hardcoded Credentials
CVE-2018-11311remotehardware25 jun 2020
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack
28RIESGO
abrir
GitHub PoC1
cyberharsh/DrupalCVE-2018-7602
CVE-2018-7602CRITICALbajo ataqueransomware25 jun 2020
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
GitHub PoC
cyberharsh/Tomcat-CVE-2017-12615
CVE-2017-12615HIGHbajo ataqueransomware24 jun 2020
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC1
cyberharsh/Oracle-mysql-CVE-2012-2122
CVE-2012-212224 jun 2020
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir
GitHub PoC
cyberharsh/Php-unit-CVE-2017-9841
CVE-2017-9841CRITICALbajo ataque24 jun 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC
Bludit 3.9.2 - bruteforce bypass - CVE-2019-17240
CVE-2019-17240LOW24 jun 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
VulnCheck XDB
local
CVE-2020-1048HIGH23 jun 2020
Windows Print Spooler Elevation of Privilege Vulnerability
61RIESGO
abrir
Exploit-DB
Lansweeper 7.2 - Incorrect Access Control
CVE-2020-14011localwindows23 jun 2020
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin accoun
28RIESGO
abrir
GitHub PoC
cyberharsh/Groovy-scripting-engine-CVE-2015-1427
CVE-2015-1427CRITICALbajo ataque22 jun 2020
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
GitHub PoC1
Python version of Metasploit exploit for CVE-2004-1561
CVE-2004-156122 jun 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
Metasploit600
Rockwell FactoryTalk View SE SCADA Unauthenticated Remote Code Execution
CVE-2020-12029CRITICAL22 jun 2020
Rockwell Automation FactoryTalk View SE
75RIESGO
abrir
Metasploit600
Rockwell FactoryTalk View SE SCADA Unauthenticated Remote Code Execution
CVE-2020-12028HIGH22 jun 2020
Rockwell Automation FactoryTalk View SE
48RIESGO
abrir
Metasploit600
Rockwell FactoryTalk View SE SCADA Unauthenticated Remote Code Execution
CVE-2020-12027MEDIUM22 jun 2020
Rockwell Automation FactoryTalk View SE
40RIESGO
abrir
Exploit-DB
WebPort 1.19.1 - 'setup' Reflected Cross-Site Scripting
CVE-2019-12460webappsphp22 jun 2020
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
23RIESGO
abrir
Exploit-DB
WebPort 1.19.1 - Reflected Cross-Site Scripting
CVE-2019-12461webappsmultiple22 jun 2020
Web Port 1.19.1 allows XSS via the /log type parameter.
38RIESGO
abrir
Exploit-DB
FileRun 2019.05.21 - Reflected Cross-Site Scripting
CVE-2019-12905webappsmultiple22 jun 2020
FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman&section=do&page=up URI. This issue has been fixed
23RIESGO
abrir
Metasploit600
ZenTao Pro 8.8.2 Remote Code Execution
CVE-2020-7361CRITICAL20 jun 2020
ZenTao Pro Command Injection
48RIESGO
abrir
GitHub PoC
cdedmondson/Modified-CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware20 jun 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC3
cyberharsh/Nginx-CVE-2013-4547
CVE-2013-454720 jun 2020
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescap
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware20 jun 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2551CRITICALbajo ataque20 jun 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-7921CRITICALbajo ataque19 jun 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2551CRITICALbajo ataque19 jun 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
GitHub PoC60
CVE-2020-8163 - Remote code execution of user-provided local names in Rails
CVE-2020-816319 jun 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALbajo ataqueransomware19 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC1
cyberharsh/Apache-couchdb-CVE-2017-12635
CVE-2017-1263519 jun 2020
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC
cyberharsh/Libssh-server-CVE-2018-10933
CVE-2018-10933CRITICAL19 jun 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC20
This is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework
CVE-2020-0796CRITICALbajo ataqueransomware19 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware18 jun 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
anteriorpágina 765 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.