Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
VulnCheck XDB
local
CVE-2020-0041HIGHbajo ataque31 mar 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RIESGO
abrir
Metasploit600
Nexus Repository Manager Java EL Injection RCE
CVE-2020-10199HIGHbajo ataque31 mar 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
Metasploit300
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump
CVE-2020-572330 mar 2020
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an atta
18RIESGO
abrir
Metasploit300
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump
CVE-2020-572430 mar 2020
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo
23RIESGO
abrir
GitHub PoC14
CVE-2020-8515-PoC
CVE-2020-8515CRITICALbajo ataque30 mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RIESGO
abrir
GitHub PoC
Exploit for the CVE-2019-16278 vulnerability
CVE-2019-16278CRITICALbajo ataque30 mar 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
Exploit-DB
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation
CVE-2020-0796CRITICALbajo ataqueransomwarelocalwindows30 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
tripledd/cve-2020-0796-vuln
CVE-2020-0796CRITICALbajo ataqueransomware30 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC1359
CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost
CVE-2020-0796CRITICALbajo ataqueransomware30 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALbajo ataqueransomware30 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC244
CVE-2020-0796 Local Privilege Escalation POC
CVE-2020-0796CRITICALbajo ataqueransomware30 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Exploit-DB
Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
CVE-2020-8515CRITICALbajo ataqueremotelinux30 mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque30 mar 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-8515CRITICALbajo ataque30 mar 2020
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALbajo ataque29 mar 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2018-8639HIGHbajo ataqueransomware28 mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-5786MEDIUMbajo ataque28 mar 2020
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RIESGO
abrir
Metasploit400
Pi-Hole DHCP MAC OS Command Execution
CVE-2020-8816CRITICALbajo ataque28 mar 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
GitHub PoC7
Icecast Header Overwrite buffer overflow RCE < 2.0.1 (Win32)
CVE-2004-156127 mar 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
GitHub PoC8
CVE-2020-1938 / CNVD-2020-1048 Detection Tools
CVE-2020-1938CRITICALbajo ataque27 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALbajo ataque27 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC1
CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool.
CVE-2019-17558HIGHbajo ataque27 mar 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
GitHub PoC1
CVE 2018-16763
CVE-2018-1676326 mar 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
Metasploit600
GitLab File Read Remote Code Execution
CVE-2020-1097726 mar 2020
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
30RIESGO
abrir
Exploit-DB
TP-Link Archer C50 3 - Denial of Service (PoC)
CVE-2020-9375doshardware26 mar 2020
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a
28RIESGO
abrir
GitHub PoC118
mzer0one/CVE-2020-7961-POC
CVE-2020-7961CRITICALbajo ataque26 mar 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676326 mar 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALbajo ataque26 mar 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
Exploit-DB
LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
CVE-2020-12707webappsphp25 mar 2020
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only secur
23RIESGO
abrir
GitHub PoC20
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.
CVE-2020-937525 mar 2020
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a
28RIESGO
abrir
anteriorpágina 780 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.