Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
GitHub PoC106
dozernz/cve-2020-11651
CVE-2020-11651CRITICALbajo ataque04 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC40
CVE-2020-11651: Proof of Concept
CVE-2020-11651CRITICALbajo ataque04 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC5
POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability
CVE-2020-3153MEDIUMbajo ataqueransomware04 may 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RIESGO
abrir
GitHub PoC5
CVE-2020-11651&&CVE-2020-11652 EXP
CVE-2020-11651CRITICALbajo ataque04 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC6
PoC for CVE-2020-11651
CVE-2020-11651CRITICALbajo ataque04 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8639HIGHbajo ataqueransomware02 may 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RIESGO
abrir
GitHub PoC
sumedhaDharmasena/-Kernel-ptrace-c-mishandles-vulnerability-CVE-2019-13272
CVE-2019-13272HIGHbajo ataque02 may 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC
Billith/CVE-2019-5736-PoC
CVE-2019-573601 may 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
VulnCheck XDB
local
CVE-2019-573601 may 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC108
Salt security backports for CVE-2020-11651 & CVE-2020-11652
CVE-2020-11651CRITICALbajo ataque01 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC6
Checks for CVE-2020-11651 and CVE-2020-11652
CVE-2020-11651CRITICALbajo ataque01 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque01 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
CVE-2016-4437CRITICALbajo ataqueremotemultiple01 may 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
Exploit-DB
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
CVE-2019-0235webappsjava01 may 2020
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
35RIESGO
abrir
Metasploit300
SaltStack Salt Master Server Root Key Disclosure
CVE-2020-11652MEDIUMbajo ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-11882HIGHbajo ataqueransomware30 abr 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Metasploit300
WebLogic Server Deserialization RCE BadAttributeValueExpException ExtComp
CVE-2020-2883CRITICALbajo ataque30 abr 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware30 abr 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
CVE-2020-11651CRITICALbajo ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
CVE-2020-11652MEDIUMbajo ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Metasploit300
SaltStack Salt Master Server Root Key Disclosure
CVE-2020-11651CRITICALbajo ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Metasploit300
Wordpress LearnPress current_items Authenticated SQLi
CVE-2020-601029 abr 2020
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
50RIESGO
abrir
Metasploit600
TP-Link Cloud Cameras NCXXX Bonjour Command Injection
CVE-2020-1210929 abr 2020
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220
40RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALbajo ataque29 abr 2020
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC1
yukar1z0e/CVE-2018-14847
CVE-2018-14847CRITICALbajo ataque29 abr 2020
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Exploit-DBVexDay Proof
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
CVE-2019-3999localwindows29 abr 2020
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RIESGO
abrir
Exploit-DBVexDay Proof
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
CVE-2019-15752HIGHbajo ataquelocalwindows28 abr 2020
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RIESGO
abrir
Metasploit600
Netsweeper WebAdmin unixlogin.php Python Code Injection
CVE-2020-1316728 abr 2020
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain
40RIESGO
abrir
Metasploit600
GOG GalaxyClientService Privilege Escalation
CVE-2020-7352HIGH28 abr 2020
GOG Galaxy GalaxyClientService Privilege Escalation
36RIESGO
abrir
Metasploit600
TrixBox CE endpoint_devicemap.php Authenticated Command Execution
CVE-2020-7351HIGH28 abr 2020
Fonality Trixbox CE Post-Authentication Command Injection
48RIESGO
abrir
anteriorpágina 774 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.