Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
Print Spooler Remote DLL Injection
CVE-2021-1675HIGHbajo ataqueransomware08 jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Polkit D-Bus Authentication Bypass
CVE-2021-3560HIGHbajo ataque03 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180727 may 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to
23RIESGO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180627 may 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a
40RIESGO
abrir
Metasploit600
VMware vCenter Server Virtual SAN Health Check Plugin RCE
CVE-2021-21985CRITICALbajo ataqueransomware25 may 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
Metasploit600
ExifTool DjVu ANT Perl injection
CVE-2021-22204MEDIUMbajo ataque24 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
Metasploit600
IPFire 2.25 Core Update 156 and Prior pakfire.cgi Authenticated RCE
CVE-2021-3339317 may 2021
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It
50RIESGO
abrir
Metasploit300
Windows IIS HTTP Protocol Stack DOS
CVE-2021-31166CRITICALbajo ataque11 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit500
Linux eBPF ALU32 32-bit Invalid Bounds Tracking LPE
CVE-2021-3490HIGH11 may 2021
Linux kernel eBPF bitwise ops ALU32 bounds tracking
41RIESGO
abrir
Metasploit600
Microsoft SharePoint Unsafe Control and ViewState RCE
CVE-2021-31181HIGH11 may 2021
Microsoft SharePoint Remote Code Execution Vulnerability
48RIESGO
abrir
Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
CVE-2021-41773HIGHbajo ataqueransomware10 may 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
CVE-2021-41773HIGHbajo ataqueransomware10 may 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
CVE-2021-42013CRITICALbajo ataqueransomware10 may 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
CVE-2021-42013CRITICALbajo ataqueransomware10 may 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Metasploit600
Cisco HyperFlex HX Data Platform Command Execution
CVE-2021-1497CRITICALbajo ataque05 may 2021
Cisco HyperFlex HX Command Injection Vulnerabilities
100RIESGO
abrir
Metasploit600
Cisco HyperFlex HX Data Platform Command Execution
CVE-2021-1498CRITICALbajo ataque05 may 2021
Cisco HyperFlex HX Command Injection Vulnerabilities
100RIESGO
abrir
Metasploit600
Cisco HyperFlex HX Data Platform unauthenticated file upload to RCE (CVE-2021-1499)
CVE-2021-1499MEDIUM05 may 2021
Cisco HyperFlex HX Data Platform File Upload Vulnerability
50RIESGO
abrir
Metasploit400
Dell DBUtil_2_3.sys IOCTL memmove
CVE-2021-21551HIGHbajo ataque04 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
Metasploit600
Wordpress Plugin Backup Guard - Authenticated Remote Code Execution
CVE-2021-2415504 may 2021
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RIESGO
abrir
Metasploit400
SuiteCRM Log File Remote Code Execution
CVE-2021-4284028 abr 2021
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RIESGO
abrir
Metasploit400
SuiteCRM Log File Remote Code Execution
CVE-2020-2832828 abr 2021
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain
50RIESGO
abrir
Metasploit600
Git LFS Clone Command Exec
CVE-2021-21300HIGH26 abr 2021
malicious repositories can execute remote code while cloning
58RIESGO
abrir
Metasploit300
Netgear R7000 backup.cgi Heap Overflow RCE
CVE-2021-3180221 abr 2021
NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without au
23RIESGO
abrir
Metasploit500
Pi-Hole Remove Commands Linux Priv Esc
CVE-2021-29449MEDIUM20 abr 2021
Multiple Privilege Escalation Vulnerabilities Pihole
28RIESGO
abrir
Metasploit300
Apache Tapestry HMAC secret key leak
CVE-2021-2785015 abr 2021
Bypass of the fix for CVE-2019-0195
60RIESGO
abrir
Metasploit600
GitLab Unauthenticated Remote ExifTool Command Injection
CVE-2021-22204MEDIUMbajo ataque14 abr 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
Metasploit600
GitLab Unauthenticated Remote ExifTool Command Injection
CVE-2021-22205CRITICALbajo ataqueransomware14 abr 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
Metasploit300
Cockpit CMS NoSQLi to RCE
CVE-2020-3584713 abr 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
60RIESGO
abrir
Metasploit0
Google Chrome versions before 89.0.4389.128 V8 XOR Typer Out-Of-Bounds Access RCE
CVE-2021-21220HIGHbajo ataque13 abr 2021
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
98RIESGO
abrir
Metasploit300
Cockpit CMS NoSQLi to RCE
CVE-2020-3584613 abr 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
40RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.