Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
WordPress Plugin Automatic Config Change to RCE
CVE-2021-4374CRITICAL06 sep 2021
WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update
48RIESGO
abrir
Metasploit600
Atlassian Confluence WebWork OGNL Injection
CVE-2021-26084CRITICALbajo ataqueransomware25 ago 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
Metasploit300
Canon Driver Privilege Escalation
CVE-2021-3808507 ago 2021
The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer pro
18RIESGO
abrir
Metasploit300
Pi-Hole Top Domains API Authenticated Exec
CVE-2021-32706HIGH04 ago 2021
(Authenticated) Remote Code Execution Possible in Web Interface 5.5
48RIESGO
abrir
Metasploit600
ManageEngine OpManager SumPDU Java Deserialization
CVE-2021-328726 jul 2021
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the
30RIESGO
abrir
Metasploit600
ManageEngine OpManager SumPDU Java Deserialization
CVE-2020-2865326 jul 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RIESGO
abrir
Metasploit300
Elasticsearch Memory Disclosure
CVE-2021-2214521 jul 2021
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
60RIESGO
abrir
Metasploit300
Windows SAM secrets leak - HiveNightmare
CVE-2021-36934HIGHbajo ataque20 jul 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
Metasploit600
Nagios XI Autodiscovery Webshell Upload
CVE-2021-3734315 jul 2021
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post au
23RIESGO
abrir
Metasploit300
Jetty WEB-INF File Disclosure
CVE-2021-34429MEDIUM15 jul 2021
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RIESGO
abrir
Metasploit300
Lexmark Driver Privilege Escalation
CVE-2021-3544915 jul 2021
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below,
18RIESGO
abrir
Metasploit300
Jetty WEB-INF File Disclosure
CVE-2021-28164MEDIUM15 jul 2021
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RIESGO
abrir
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33543CRITICAL08 jul 2021
UDP Technology/Geutebrück camera devices: Authentication Bypass
65RIESGO
abrir
Metasploit600
Geutebruck instantrec Remote Command Execution
CVE-2021-33549HIGH08 jul 2021
UDP Technology/Geutebrück camera devices: Buffer overflow in action parameter leading to RCE
48RIESGO
abrir
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33548HIGH08 jul 2021
UDP Technology/Geutebrück camera devices: Command injection in preserve parameter leading to RCE
48RIESGO
abrir
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33553HIGH08 jul 2021
UDP Technology/Geutebrück camera devices: Command injection in command parameter leading to RCE
48RIESGO
abrir
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33552HIGH08 jul 2021
UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
48RIESGO
abrir
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33550HIGH08 jul 2021
UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
48RIESGO
abrir
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33554HIGH08 jul 2021
UDP Technology/Geutebrück camera devices: Command injection in appfile.filename parameter leading to RCE
48RIESGO
abrir
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33551HIGH08 jul 2021
UDP Technology/Geutebrück camera devices: Command injection in environment.lang parameter leading to RCE
48RIESGO
abrir
Metasploit600
Geutebruck Multiple Remote Command Execution
CVE-2021-33544HIGH08 jul 2021
UDP Technology/Geutebrück camera devices: command injection leading to RCE
58RIESGO
abrir
Metasploit500
Netfilter x_tables Heap OOB Write Privilege Escalation
CVE-2021-22555HIGHbajo ataque07 jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
CVE-2020-7387MEDIUM07 jul 2021
Sage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actor
40RIESGO
abrir
Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
CVE-2020-7388CRITICAL07 jul 2021
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
75RIESGO
abrir
Metasploit600
ForgeRock / OpenAM Jato Java Deserialization
CVE-2021-35464CRITICALbajo ataqueransomware29 jun 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir
Metasploit600
Moodle SpellChecker Path Authenticated Remote Command Execution
CVE-2021-21809HIGH22 jun 2021
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted s
41RIESGO
abrir
Metasploit600
Wordpress Plugin SP Project and Document - Authenticated Remote Code Execution
CVE-2021-2434714 jun 2021
SP Project & Document Manager <2 4.22 - Authenticated Shell Upload
30RIESGO
abrir
Metasploit600
elFinder Archive Command Injection
CVE-2021-32682CRITICAL13 jun 2021
Multiple vulnerabilities leading to RCE
75RIESGO
abrir
Metasploit300
Wordpress Popular Posts Authenticated RCE
CVE-2021-42362HIGH11 jun 2021
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RIESGO
abrir
Metasploit300
Print Spooler Remote DLL Injection
CVE-2021-34527HIGHbajo ataqueransomware08 jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.