Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
Exploit-DBVexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
CVE-2018-15812remotewindows16 abr 2020
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-3952CRITICALbajo ataque16 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
GitHub PoC11
CVE-2020-5260演示记录
CVE-2020-5260CRITICAL16 abr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RIESGO
abrir
GitHub PoC
https://bugs.chromium.org/p/project-zero/issues/detail?id=2021
CVE-2020-5260CRITICAL15 abr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RIESGO
abrir
GitHub PoC37
A HTTP PoC Endpoint for cve-2020-5260 which can be deployed to Heroku
CVE-2020-5260CRITICAL15 abr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RIESGO
abrir
Metasploit600
Cisco UCS Director Cloupia Script RCE
CVE-2020-3250CRITICAL15 abr 2020
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
75RIESGO
abrir
Metasploit600
Cisco UCS Director Cloupia Script RCE
CVE-2020-3243CRITICAL15 abr 2020
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
85RIESGO
abrir
GitHub PoC4
Vuln Check
CVE-2020-3952CRITICALbajo ataque15 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-20085HIGHbajo ataque15 abr 2020
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
GitHub PoC6
NVMS 1000 - Directory Traversal Attack Exploit for CVE-2019-20085
CVE-2019-20085HIGHbajo ataque15 abr 2020
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2016-6415HIGHbajo ataque15 abr 2020
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RIESGO
abrir
Metasploit300
Veeam ONE Agent .NET Deserialization
CVE-2020-10915CRITICAL15 abr 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
85RIESGO
abrir
Metasploit300
Veeam ONE Agent .NET Deserialization
CVE-2020-10914CRITICAL15 abr 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
75RIESGO
abrir
Exploit-DB
Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
CVE-2020-2555CRITICALbajo ataquewebappsjava14 abr 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
GitHub PoC
This tool helps scan large subnets for cve-2020-0796 vulnerable systems
CVE-2020-0796CRITICALbajo ataqueransomware14 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC27
patches for SNYK-JS-JQUERY-565129, SNYK-JS-JQUERY-567880, CVE-2020-1102, CVE-2020-11023, includes the patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
CVE-2019-1135814 abr 2020
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALbajo ataque14 abr 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC
Reproduction of privilege escalation breach CVE-2019-3010
CVE-2019-3010HIGHbajo ataque13 abr 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir
VulnCheck XDB
local
CVE-2019-3010HIGHbajo ataque13 abr 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir
Exploit-DB
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
CVE-2019-16383webappsphp13 abr 2020
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 a
23RIESGO
abrir
Exploit-DB
TVT NVMS 1000 - Directory Traversal
CVE-2019-20085HIGHbajo ataquewebappshardware13 abr 2020
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
GitHub PoC19
Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)
CVE-2018-19320HIGHbajo ataqueransomware13 abr 2020
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-0199HIGHbajo ataqueransomware13 abr 2020
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-19320HIGHbajo ataqueransomware13 abr 2020
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-11707HIGHbajo ataque13 abr 2020
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
GitHub PoC2
https://bugs.chromium.org/p/project-zero/issues/detail?id=1820
CVE-2019-11707HIGHbajo ataque13 abr 2020
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
GitHub PoC8
CVE-2018-7600【Drupal7】批量扫描工具。
CVE-2018-7600CRITICALbajo ataqueransomware12 abr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware12 abr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
Code execution for CVE-2017-11176
CVE-2017-1117610 abr 2020
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RIESGO
abrir
Metasploit300
Zen Load Balancer Directory Traversal
CVE-2020-1149110 abr 2020
Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attac
18RIESGO
abrir
anteriorpágina 777 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.