Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALbajo ataqueransomware20 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Exploit-DBVexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
CVE-2020-5847CRITICALbajo ataqueremotelinux20 abr 2020
Unraid through 6.8.0 allows Remote Code Execution.
100RIESGO
abrir
GitHub PoC
darren646/CVE-2019-19781POC
CVE-2019-19781CRITICALbajo ataqueransomware20 abr 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-3952CRITICALbajo ataque19 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
GitHub PoC4
Exploit for CVE-2020-3952 in vCenter 6.7 https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/
CVE-2020-3952CRITICALbajo ataque19 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
GitHub PoC
kristyna-mlcakova/CVE-2018-10933
CVE-2018-10933CRITICAL19 abr 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC1
D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1
CVE-2019-1752518 abr 2020
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and
23RIESGO
abrir
Exploit-DB
Cisco IP Phone 11.7 - Denial of service (PoC)
CVE-2020-3161CRITICALbajo ataquedoshardware17 abr 2020
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-3952CRITICALbajo ataque17 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
Exploit-DBVexDay Proof
Nexus Repository Manager - Java EL Injection RCE (Metasploit)
CVE-2020-10199HIGHbajo ataqueremotelinux17 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
GitHub PoC2
VMWare vmdir missing access control exploit checker
CVE-2020-3952CRITICALbajo ataque17 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
Metasploit0
Kibana Upgrade Assistant Telemetry Collector Prototype Pollution
CVE-2020-701217 abr 2020
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authen
23RIESGO
abrir
Metasploit300
SpamTitan Unauthenticated RCE
CVE-2020-1169817 abr 2020
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RIESGO
abrir
Exploit-DBVexDay Proof
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
CVE-2020-10884HIGHremotelinux_mips16 abr 2020
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer
61RIESGO
abrir
Exploit-DBVexDay Proof
PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metasploit)
CVE-2020-8644CRITICALbajo ataqueremotephp16 abr 2020
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RIESGO
abrir
GitHub PoC11
CVE-2020-5260演示记录
CVE-2020-5260CRITICAL16 abr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RIESGO
abrir
Exploit-DBVexDay Proof
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
CVE-2020-7961CRITICALbajo ataqueremotejava16 abr 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2017-9822HIGHbajo ataqueransomwareremotewindows16 abr 2020
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RIESGO
abrir
GitHub PoC274
Exploit for CVE-2020-3952 in vCenter 6.7
CVE-2020-3952CRITICALbajo ataque16 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
Exploit-DBVexDay Proof
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
CVE-2020-10883MEDIUMremotelinux_mips16 abr 2020
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware
48RIESGO
abrir
Exploit-DBVexDay Proof
VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
CVE-2020-3950HIGHbajo ataquelocalmacos16 abr 2020
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RIESGO
abrir
GitHub PoC28
This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.
CVE-2019-11510CRITICALbajo ataqueransomware16 abr 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2018-18325HIGHbajo ataqueremotewindows16 abr 2020
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue ex
100RIESGO
abrir
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2018-15812remotewindows16 abr 2020
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect
50RIESGO
abrir
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2018-18326remotewindows16 abr 2020
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expect
50RIESGO
abrir
Exploit-DBVexDay Proof
ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
CVE-2018-20062CRITICALbajo ataqueremotelinux16 abr 2020
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
CVE-2019-17558HIGHbajo ataqueremotemultiple16 abr 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHbajo ataque16 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
Exploit-DBVexDay Proof
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
CVE-2020-10882HIGHremotelinux_mips16 abr 2020
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
68RIESGO
abrir
Exploit-DBVexDay Proof
ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
CVE-2019-9082HIGHbajo ataqueremotelinux16 abr 2020
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RIESGO
abrir
anteriorpágina 776 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.