Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
GitHub PoC9
CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates
CVE-2020-0796CRITICALbajo ataqueransomware11 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC162
NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473
CVE-2020-1350CRITICALbajo ataque11 mar 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC14
Script that checks if the system is vulnerable to CVE-2020-0796 (SMB v3.1.1)
CVE-2020-0796CRITICALbajo ataqueransomware11 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC18
Weaponized PoC for SMBv3 TCP codec/compression vulnerability
CVE-2020-0796CRITICALbajo ataqueransomware10 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Exploit-DB
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
CVE-2020-8518webappsphp10 mar 2020
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
60RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI - Authenticated Remote Command Execution (Metasploit)
CVE-2019-15949HIGHbajo ataqueremotelinux10 mar 2020
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir
GitHub PoC14
CVE-2020-2555
CVE-2020-2555CRITICALbajo ataque10 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
Metasploit600
Background Intelligent Transfer Service Arbitrary File Move Privilege Elevation Vulnerability
CVE-2020-0787HIGHbajo ataqueransomware10 mar 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir
Metasploit300
CVE-2020-1170 Cloud Filter Arbitrary File Creation EOP
CVE-2020-17136HIGH10 mar 2020
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
CVE-2020-6418HIGHbajo ataqueremotemultiple09 mar 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome 67_ 68 and 69 - Object.create Type Confusion (Metasploit)
CVE-2018-17463HIGHbajo ataqueremotemultiple09 mar 2020
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
CVE-2019-5825MEDIUMbajo ataqueremotemultiple09 mar 2020
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RIESGO
abrir
GitHub PoC1
exploit for sudo CVE-2019-18634
CVE-2019-1863409 mar 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
Metasploit600
Pandora FMS Ping Authenticated Remote Code Execution
CVE-2025-34088HIGH09 mar 2020
Pandora FMS Authenticated Remote Code Execution via Ping Module
36RIESGO
abrir
GitHub PoC13
PoC of CVE-2019-15126 kr00k vulnerability
CVE-2019-1512609 mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
CVE-2020-8794locallinux09 mar 2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RIESGO
abrir
Exploit-DBVexDay Proof
PHP-FPM - Underflow Remote Code Execution (Metasploit)
CVE-2019-11043HIGHbajo ataqueransomwareremotephp09 mar 2020
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
CVE-2015-1830remotewindows09 mar 2020
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALbajo ataqueransomware08 mar 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC1
Gather a list of Citrix appliances in a country / state pair, and check if they're vulnerable to CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware08 mar 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC177
Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE
CVE-2020-2555CRITICALbajo ataque07 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
GitHub PoC
simple poc for CVE-2020-0069
CVE-2020-0069HIGHbajo ataque07 mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RIESGO
abrir
GitHub PoC47
CVE-2020-8597 pppd buffer overflow poc
CVE-2020-8597CRITICAL07 mar 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALbajo ataque07 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware07 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-7269CRITICALbajo ataque07 mar 2020
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2012-268806 mar 2020
Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.
28RIESGO
abrir
GitHub PoC6
A CVE-2019-11580 shell
CVE-2019-11580CRITICALbajo ataqueransomware06 mar 2020
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RIESGO
abrir
GitHub PoC
CVE-2020-8597
CVE-2020-8597CRITICAL06 mar 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALbajo ataque06 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
anteriorpágina 784 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.