Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8655HIGHbajo ataqueremotemultiple05 mar 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RIESGO
abrir
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8657CRITICALbajo ataqueremotemultiple05 mar 2020
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RIESGO
abrir
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8656remotemultiple05 mar 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RIESGO
abrir
Exploit-DBVexDay Proof
Exchange Control Panel - Viewstate Deserialization (Metasploit)
CVE-2020-0688HIGHbajo ataqueransomwareremotewindows05 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Exploit-DBVexDay Proof
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
CVE-2020-8654remotemultiple05 mar 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
CVE-2015-7611remotelinux24 feb 2020
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst
50RIESGO
abrir
Exploit-DBVexDay Proof
Android Binder - Use-After-Free (Metasploit)
CVE-2019-2215HIGHbajo ataquelocalandroid24 feb 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
Exploit-DBVexDay Proof
Anviz CrossChex - Buffer Overflow (Metasploit)
CVE-2019-12518remotewindows17 feb 2020
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
50RIESGO
abrir
Exploit-DBVexDay Proof
HP System Event Utility - Local Privilege Escalation
CVE-2019-18915localwindows12 feb 2020
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
CVE-2020-7247CRITICALbajo ataqueremoteopenbsd11 feb 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
CVE-2020-7247CRITICALbajo ataqueremotelinux10 feb 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Exploit-DBVexDay Proof
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
CVE-2020-3837HIGHbajo ataquedosmultiple10 feb 2020
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
76RIESGO
abrir
Exploit-DBVexDay Proof
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
CVE-2019-20215remotelinux_mips10 feb 2020
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RIESGO
abrir
Exploit-DBVexDay Proof
Ricoh Driver - Privilege Escalation (Metasploit)
CVE-2019-19363localwindows10 feb 2020
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RIESGO
abrir
Exploit-DBVexDay Proof
Windscribe - WindscribeService Named Pipe Privilege Escalation (Metasploit)
CVE-2018-11479localwindows07 feb 2020
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
43RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
CVE-2019-15976CRITICALwebappsjava06 feb 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
70RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2 - Remote Code Execution
CVE-2019-15975CRITICALwebappsjava06 feb 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
85RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
CVE-2019-15977CRITICALwebappsjava06 feb 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
60RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
CVE-2019-15978HIGHwebappsjava06 feb 2020
Cisco Data Center Network Manager Command Injection Vulnerabilities
53RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
CVE-2019-15984HIGHwebappsjava06 feb 2020
Cisco Data Center Network Manager SQL Injection Vulnerabilities
53RIESGO
abrir
Exploit-DBVexDay Proof
rConfig 3.9.3 - Authenticated Remote Code Execution
CVE-2019-19509webappsphp30 ene 2020
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RIESGO
abrir
Exploit-DBVexDay Proof
OpenSMTPD 6.6.1 - Remote Code Execution
CVE-2020-7247CRITICALbajo ataqueremotelinux30 ene 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Exploit-DBVexDay Proof
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
CVE-2020-7991webappsphp28 ene 2020
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
23RIESGO
abrir
Exploit-DBVexDay Proof
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
CVE-2019-9213locallinux23 ene 2020
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RIESGO
abrir
Exploit-DBVexDay Proof
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
CVE-2018-5333locallinux23 ene 2020
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
43RIESGO
abrir
Exploit-DBVexDay Proof
Plantronics Hub 3.13.2 - SpokesUpdateService Privilege Escalation (Metasploit)
CVE-2019-15742localwindows17 ene 2020
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RIESGO
abrir
Exploit-DBVexDay Proof
Barco WePresent - file_transfer.cgi Command Injection (Metasploit)
CVE-2019-3929CRITICALbajo ataqueremotelinux15 ene 2020
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir
Exploit-DBVexDay Proof
Android - ashmem Readonly Bypasses via remap_file_pages() and ASHMEM_UNPIN
CVE-2020-0009dosandroid14 ene 2020
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This
23RIESGO
abrir
Exploit-DBVexDay Proof
TotalAV 2020 4.14.31 - Privilege Escalation
CVE-2019-18194localwindows10 ene 2020
TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junctio
23RIESGO
abrir
Exploit-DBVexDay Proof
JetBrains TeamCity 2018.2.4 - Remote Code Execution
CVE-2019-15039remotejava08 ene 2020
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.