Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALbajo ataque06 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
GitHub PoC45
CVE-2020-2555 Python POC
CVE-2020-2555CRITICALbajo ataque06 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
GitHub PoC3
Hu3sky/CVE-2020-2555
CVE-2020-2555CRITICALbajo ataque06 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
Metasploit500
ManageEngine Desktop Central Java Deserialization
CVE-2020-10189CRITICALbajo ataque05 mar 2020
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RIESGO
abrir
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8656remotemultiple05 mar 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RIESGO
abrir
Exploit-DBVexDay Proof
Exchange Control Panel - Viewstate Deserialization (Metasploit)
CVE-2020-0688HIGHbajo ataqueransomwareremotewindows05 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8654remotemultiple05 mar 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RIESGO
abrir
GitHub PoC
CVE-2019-13272
CVE-2019-13272HIGHbajo ataque05 mar 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8655HIGHbajo ataqueremotemultiple05 mar 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-865605 mar 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RIESGO
abrir
VulnCheck XDB
local
CVE-2019-13272HIGHbajo ataque05 mar 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8657CRITICALbajo ataqueremotemultiple05 mar 2020
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-8655HIGHbajo ataque05 mar 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RIESGO
abrir
Metasploit600
Metasploit Libnotify Plugin Arbitrary Command Execution
CVE-2020-7350MEDIUM04 mar 2020
Metasploit Framework Plugin Libnotify Command Injection
28RIESGO
abrir
GitHub PoC5
PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell
CVE-2020-0688HIGHbajo ataqueransomware04 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Exploit-DB
Microsoft Windows - 'WizardOpium' Local Privilege Escalation
CVE-2019-1458HIGHbajo ataqueransomwarelocalwindows03 mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC
exploitblizzard/CVE-2020-0601-spoofkey
CVE-2020-0601HIGHbajo ataque03 mar 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8776webappsphp03 mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a
23RIESGO
abrir
GitHub PoC
PoC of CVE
CVE-2020-6418HIGHbajo ataque03 mar 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir
GitHub PoC181
POC for cve-2019-1458
CVE-2019-1458HIGHbajo ataqueransomware03 mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-1458HIGHbajo ataqueransomware03 mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC
CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque03 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8778webappsphp03 mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document,
23RIESGO
abrir
GitHub PoC17
reversing mtk-su
CVE-2020-0069HIGHbajo ataque03 mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RIESGO
abrir
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8777webappsphp03 mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo,
23RIESGO
abrir
Metasploit600
SharePoint Workflows XOML Injection
CVE-2020-0646CRITICALbajo ataque02 mar 2020
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RIESGO
abrir
GitHub PoC11
This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.
CVE-2018-6789CRITICALbajo ataqueransomware02 mar 2020
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
Exploit-DB
Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
CVE-2019-19142webappshardware02 mar 2020
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmwa
23RIESGO
abrir
GitHub PoC132
CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 WebLogic T3 payload exploit poc python3,
CVE-2020-2546CRITICAL02 mar 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - Java
48RIESGO
abrir
Exploit-DB
TP LINK TL-WR849N - Remote Code Execution
CVE-2020-9374webappshardware02 mar 2020
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit
35RIESGO
abrir
anteriorpágina 785 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.