Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALbajo ataque03 abr 2020
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC2
rhbb/CVE-2019-17671
CVE-2019-1767103 abr 2020
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m
50RIESGO
abrir
GitHub PoC1
rhbb/CVE-2019-7609
CVE-2019-7609CRITICALbajo ataque03 abr 2020
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC31
This is a writeup for CVE-2020-11107 reported by Maximilian Barz
CVE-2020-1110703 abr 2020
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RIESGO
abrir
GitHub PoC33
该资源为CVE-2020-0796漏洞复现,包括Python版本和C++版本。主要是集合了github大神们的资源,希望您喜欢~
CVE-2020-0796CRITICALbajo ataqueransomware02 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Metasploit300
LimeSurvey Zip Path Traversals
CVE-2019-996002 abr 2020
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relati
23RIESGO
abrir
Metasploit300
LimeSurvey Zip Path Traversals
CVE-2020-1145502 abr 2020
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileM
60RIESGO
abrir
GitHub PoC1
CVE-2020-0796-EXP
CVE-2020-0796CRITICALbajo ataqueransomware02 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC4291
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
CVE-2020-14882CRITICALbajo ataque01 abr 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC65
jiansiting/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware01 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC4291
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
CVE-2019-17558HIGHbajo ataque01 abr 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque01 abr 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-17558HIGHbajo ataque01 abr 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALbajo ataqueransomware01 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALbajo ataqueransomware01 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
A simple dos-tool
CVE-1999-001601 abr 2020
Land IP denial of service.
45RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8120HIGHbajo ataqueransomware01 abr 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC3
nmap script to detect CVE-2020-8515 on Draytek Devices
CVE-2020-8515CRITICALbajo ataque31 mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RIESGO
abrir
GitHub PoC4
Coronablue exploit
CVE-2020-0796CRITICALbajo ataqueransomware31 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC2
SMBGHOST local privilege escalation
CVE-2020-0796CRITICALbajo ataqueransomware31 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC257
Exploits for Android Binder bug CVE-2020-0041
CVE-2020-0041HIGHbajo ataque31 mar 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0041HIGHbajo ataque31 mar 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-8515CRITICALbajo ataque31 mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-2725HIGHbajo ataqueransomware31 mar 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
Exploit-DBVexDay Proof
SharePoint Workflows - XOML Injection (Metasploit)
CVE-2020-0646CRITICALbajo ataqueremotewindows31 mar 2020
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RIESGO
abrir
Exploit-DBVexDay Proof
IBM TM1 / Planning Analytics - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-4716CRITICALbajo ataqueremotemultiple31 mar 2020
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated use
100RIESGO
abrir
Exploit-DBVexDay Proof
DLINK DWL-2600 - Authenticated Remote Command Injection (Metasploit)
CVE-2019-20499remotehardware31 mar 2020
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Config
60RIESGO
abrir
GitHub PoC11
Exploitation Script for CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability"
CVE-2020-0688HIGHbajo ataqueransomware31 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Metasploit600
Nexus Repository Manager Java EL Injection RCE
CVE-2020-10199HIGHbajo ataque31 mar 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
GitHub PoC17
Windows SMBv3 LPE exploit 已编译版
CVE-2020-0796CRITICALbajo ataqueransomware31 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
anteriorpágina 779 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.