Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
GitHub PoC
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Metasploit300
Cisco 7937G SSH Privilege Escalation
CVE-2020-1613702 jun 2020
A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to re
23RIESGO
abrir
Metasploit300
Cisco 7937G Denial-of-Service Attack
CVE-2020-1613802 jun 2020
A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remot
23RIESGO
abrir
Exploit-DB
vCloud Director 9.7.0.15498291 - Remote Code Execution
CVE-2020-3956remotelinux02 jun 2020
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4
28RIESGO
abrir
Exploit-DB
OpenCart 3.0.3.2 - Stored Cross Site Scripting (Authenticated)
CVE-2020-10596webappsphp02 jun 2020
OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upl
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'SMBGhost' Remote Code Execution
CVE-2020-0796CRITICALbajo ataqueransomwareremotewindows02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALbajo ataqueransomware02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC5
Exploit for CVE-2020-9283 based on Go
CVE-2020-928302 jun 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RIESGO
abrir
GitHub PoC
CVE-2020-0796-exp
CVE-2020-0796CRITICALbajo ataqueransomware02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC89
PoC exploit for VMware Cloud Director RCE (CVE-2020-3956)
CVE-2020-395601 jun 2020
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4
28RIESGO
abrir
Exploit-DB
WordPress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
CVE-2020-13693webappsphp01 jun 2020
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi
35RIESGO
abrir
VulnCheck XDB
local
CVE-2020-106601 jun 2020
.NET Framework Elevation of Privilege Vulnerability
23RIESGO
abrir
Exploit-DB
VMware vCenter Server 6.7 - Authentication Bypass
CVE-2020-3952CRITICALbajo ataquewebappsmultiple01 jun 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
Metasploit300
Directory Traversal in Spring Cloud Config Server
CVE-2020-5410HIGHbajo ataque01 jun 2020
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-106601 jun 2020
.NET Framework Elevation of Privilege Vulnerability
23RIESGO
abrir
Exploit-DB
QuickBox Pro 2.1.8 - Authenticated Remote Code Execution
CVE-2020-13448webappsphp01 jun 2020
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execut
28RIESGO
abrir
Metasploit300
Cisco DCNM auth bypass
CVE-2019-15975CRITICAL01 jun 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
85RIESGO
abrir
GitHub PoC3
nmurilo/CVE-2008-4687-exploit
CVE-2008-468730 may 2020
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-15944CRITICALbajo ataque29 may 2020
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
GitHub PoC5
The reproduction code for CVE-2019-8641.
CVE-2019-864129 may 2020
An out-of-bounds read was addressed with improved input validation.
28RIESGO
abrir
GitHub PoC2
This project for CVE-2019-18935
CVE-2019-18935CRITICALbajo ataqueransomware29 may 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC
yukar1z0e/CVE-2017-15944
CVE-2017-15944CRITICALbajo ataque29 may 2020
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALbajo ataqueransomware29 may 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC
halsten/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware28 may 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALbajo ataqueransomware28 may 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware27 may 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC55
CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本
CVE-2016-4437CRITICALbajo ataque27 may 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware27 may 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-072827 may 2020
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-4437CRITICALbajo ataque27 may 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
anteriorpágina 768 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.