Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
GitHub PoC
BBRathnayaka/POC-CVE-2019-5736
CVE-2019-573610 may 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC
A remote code execution flaw was found in Samba. A malicious authenticated samba client, having write access to the samba share, could use this flaw to execute arbitrary code as root.
CVE-2017-7494CRITICALbajo ataqueransomware10 may 2020
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC10
A Python script to exploit CVE-2020-8816, a remote code execution vulnerability on the Pi-hole
CVE-2020-8816CRITICALbajo ataque10 may 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution
CVE-2020-11108webappslinux10 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
GitHub PoC
PoC for CVE-2020-11651
CVE-2020-11651CRITICALbajo ataque09 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque09 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC33
PoC CVE-2017-5123 - LPE - Bypassing SMEP/SMAP. No KASLR
CVE-2017-512308 may 2020
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
GitHub PoC
Project with sublist3r, massan, CVE-2018-15473, ssh bruteforce, ftp bruteforce and nikto.
CVE-2018-15473MEDIUM08 may 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-0674HIGHbajo ataque07 may 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMbajo ataque07 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC24
CVE-2020-11651&&CVE-2020-11652 EXP
CVE-2020-11651CRITICALbajo ataque07 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC222
This is an exploit for CVE-2020-0674 that runs on the x64 version of IE 8, 9, 10, and 11 on Windows 7.
CVE-2020-0674HIGHbajo ataque07 may 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque07 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Metasploit500
Bolt CMS 3.7.0 - Authenticated Remote Code Execution
CVE-2025-34086HIGH07 may 2020
Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename
36RIESGO
abrir
Metasploit300
Plex Unpickle Dict Windows RCE
CVE-2020-5741HIGHbajo ataque07 may 2020
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arb
100RIESGO
abrir
GitHub PoC5
lovelyjuice/cve-2020-11651-exp-plus
CVE-2020-11651CRITICALbajo ataque07 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALbajo ataqueransomware06 may 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALbajo ataqueransomware06 may 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALbajo ataque06 may 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHbajo ataqueransomware05 may 2020
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Exploit-DB
Saltstack 3000.1 - Remote Code Execution
CVE-2020-11651CRITICALbajo ataqueremotemultiple05 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Exploit-DB
Saltstack 3000.1 - Remote Code Execution
CVE-2020-11652MEDIUMbajo ataqueremotemultiple05 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC14
This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.
CVE-2019-11043HIGHbajo ataqueransomware05 may 2020
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-3153MEDIUMbajo ataqueransomware04 may 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMbajo ataque04 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC5
POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability
CVE-2020-3153MEDIUMbajo ataqueransomware04 may 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque04 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-11651CRITICALbajo ataque04 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque04 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque04 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
anteriorpágina 773 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.