Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.207exploits catalogados
36.419CVEs con explotación pública
24.695probados en laboratorio
79.203 exploits
GitHub PoC
N0b1e6/CVE-2018-1335-Python3
CVE-2018-133511 feb 2020
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Exploit-DB
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
CVE-2020-8825webappsphp11 feb 2020
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
CVE-2020-7247CRITICALbajo ataqueremoteopenbsd11 feb 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC336
CVE-2020-0683 - Windows MSI “Installer service” Elevation of Privilege
CVE-2020-0683HIGHbajo ataque11 feb 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RIESGO
abrir
Exploit-DB
WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting
CVE-2020-7108webappsphp10 feb 2020
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
23RIESGO
abrir
Exploit-DBVexDay Proof
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
CVE-2020-3837HIGHbajo ataquedosmultiple10 feb 2020
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
76RIESGO
abrir
Exploit-DBVexDay Proof
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
CVE-2020-7247CRITICALbajo ataqueremotelinux10 feb 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Exploit-DBVexDay Proof
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
CVE-2019-20215remotelinux_mips10 feb 2020
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RIESGO
abrir
Exploit-DBVexDay Proof
Ricoh Driver - Privilege Escalation (Metasploit)
CVE-2019-19363localwindows10 feb 2020
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RIESGO
abrir
Exploit-DB
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
CVE-2019-6146webappsmultiple10 feb 2020
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade
23RIESGO
abrir
Metasploit600
Unraid 6.8.0 Auth Bypass PHP Code Execution
CVE-2020-5847CRITICALbajo ataque10 feb 2020
Unraid through 6.8.0 allows Remote Code Execution.
100RIESGO
abrir
Exploit-DB
Dota 2 7.23f - Denial of Service (PoC)
CVE-2020-7949doswindows10 feb 2020
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by
23RIESGO
abrir
GitHub PoC3
VanillaForum 2.6.3 allows stored XSS.
CVE-2020-882510 feb 2020
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RIESGO
abrir
Metasploit600
Unraid 6.8.0 Auth Bypass PHP Code Execution
CVE-2020-5849HIGHbajo ataque10 feb 2020
Unraid 6.8.0 allows authentication bypass.
100RIESGO
abrir
GitHub PoC7
Containerized and deployable use of the CVE-2019-14287 vuln. View README.md for more.
CVE-2019-1428709 feb 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
Exhaust WordPress <V5.0.1 resources using long passwords (CVE-2014-9016)
CVE-2014-901608 feb 2020
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir
GitHub PoC
Adapted CVE-2015-8562 payload
CVE-2015-856207 feb 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
Exploit-DBVexDay Proof
Windscribe - WindscribeService Named Pipe Privilege Escalation (Metasploit)
CVE-2018-11479localwindows07 feb 2020
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
38RIESGO
abrir
Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
CVE-2020-8656webappsphp07 feb 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RIESGO
abrir
Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
CVE-2020-8655HIGHbajo ataquewebappsphp07 feb 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-856207 feb 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC59
A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc
CVE-2019-1863407 feb 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC237
Proof of Concept for CVE-2019-18634
CVE-2019-1863407 feb 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
CVE-2020-8654webappsphp07 feb 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RIESGO
abrir
Metasploit600
Horde CSV import arbitrary PHP code execution
CVE-2020-851807 feb 2020
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
60RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-865606 feb 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-8657CRITICALbajo ataque06 feb 2020
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-865406 feb 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-946506 feb 2020
An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL
40RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-8655HIGHbajo ataque06 feb 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RIESGO
abrir
anteriorpágina 790 / 2641siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.