Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.210exploits catalogados
36.420CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
CVE-2020-8425webappsphp29 ene 2020
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-0601HIGHbajo ataque29 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
Exploit-DB
Satellian 1.12 - Remote Code Execution
CVE-2020-7980webappshardware29 ene 2020
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RIESGO
abrir
Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
CVE-2020-8424webappsphp29 ene 2020
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php
23RIESGO
abrir
Exploit-DB
XMLBlueprint 16.191112 - XML External Entity Injection
CVE-2019-19032localwindows29 ene 2020
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an
23RIESGO
abrir
GitHub PoC1
proof of concept for CVE-2020-0601
CVE-2020-0601HIGHbajo ataque29 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC
ianxtianxt/CVE-2016-8735
CVE-2016-8735CRITICALbajo ataque29 ene 2020
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8
100RIESGO
abrir
Exploit-DB
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
CVE-2018-8413localwindows29 ene 2020
A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows T
35RIESGO
abrir
GitHub PoC4
TheCyberGeek/CVE-2020-5844
CVE-2020-584429 ene 2020
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t
35RIESGO
abrir
Metasploit600
OpenSMTPD MAIL FROM Remote Code Execution
CVE-2020-7247CRITICALbajo ataque28 ene 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC1
*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :) --- somhmxxghoul ---
CVE-2014-6271CRITICALbajo ataque28 ene 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-0601HIGHbajo ataque28 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
Exploit-DBVexDay Proof
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
CVE-2020-7991webappsphp28 ene 2020
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
23RIESGO
abrir
GitHub PoC1
Python CVE-2019-19781 exploit
CVE-2019-19781CRITICALbajo ataqueransomware28 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC73
PoC script that shows RCE vulnerability over Intellian Satellite controller
CVE-2020-798028 ene 2020
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-798028 ene 2020
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RIESGO
abrir
Exploit-DB
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
CVE-2019-19740webappsphp28 ene 2020
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
23RIESGO
abrir
GitHub PoC20
PoC for CVE-2020-0601 - CryptoAPI exploit
CVE-2020-0601HIGHbajo ataque28 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - Information Disclosure
CVE-2019-1125MEDIUMlocalwindows27 ene 2020
Windows Kernel Information Disclosure Vulnerability
33RIESGO
abrir
GitHub PoC41
This repository contains the sources and documentation for the SWAPGS attack PoC (CVE-2019-1125)
CVE-2019-1125MEDIUM27 ene 2020
Windows Kernel Information Disclosure Vulnerability
33RIESGO
abrir
Metasploit600
Centreon Poller Authenticated Remote Command Execution
CVE-2019-1969927 ene 2020
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers mi
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque25 ene 2020
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
PoC for "CurveBall" CVE-2020-0601
CVE-2020-0601HIGHbajo ataque25 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC
Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts
CVE-2019-19781CRITICALbajo ataqueransomware24 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
Exploit-DB
Genexis Platinum-4410 2.1 - Authentication Bypass
CVE-2020-6170webappshardware24 ene 2020
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl
23RIESGO
abrir
GitHub PoC2
Archi73ct/CVE-2020-0609
CVE-2020-060924 ene 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RIESGO
abrir
Exploit-DB
TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
CVE-2019-16893webappshardware24 ene 2020
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the
35RIESGO
abrir
GitHub PoC68
A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.
CVE-2020-060924 ene 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RIESGO
abrir
GitHub PoC78
PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610
CVE-2020-060924 ene 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RIESGO
abrir
Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
CVE-2020-0610doswindows23 ene 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RIESGO
abrir
anteriorpágina 792 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.