Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC
Metabase GeoJSON map local file inclusion
CVE-2021-41277CRITICALbajo ataque24 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
GitHub PoC
Python 3 script to identify CVE-2021-26084 via network requests.
CVE-2021-26084CRITICALbajo ataqueransomware23 nov 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC4
Vulnmachines/Metabase_CVE-2021-41277
CVE-2021-41277CRITICALbajo ataque23 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
GitHub PoC
plugin made for LeakiX
CVE-2021-41277CRITICALbajo ataque23 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
GitHub PoC83
Microsoft Exchange Server Poc
CVE-2021-42321HIGHbajo ataqueransomware23 nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC17
对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。
CVE-2021-34473CRITICALbajo ataqueransomware22 nov 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
hzshang/CVE-2021-31956
CVE-2021-31956HIGHbajo ataque22 nov 2021
Windows NTFS Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
Metabase 任意文件读取
CVE-2021-41277CRITICALbajo ataque22 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
GitHub PoC
MetaBase 任意文件读取漏洞 fofa批量poc
CVE-2021-41277CRITICALbajo ataque22 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
GitHub PoC5
simple program for exploit metabase
CVE-2021-41277CRITICALbajo ataque22 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
GitHub PoC2
CrackerCat/CVE-2021-26411
CVE-2021-26411HIGHbajo ataqueransomware22 nov 2021
Internet Explorer Memory Corruption Vulnerability
93RIESGO
abrir
GitHub PoC
Alexcot25051999/CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware22 nov 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.
CVE-2018-1676322 nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC4
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell) RCE
CVE-2020-575221 nov 2021
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir
GitHub PoC11
PoC for CVE-2021-41277
CVE-2021-41277CRITICALbajo ataque21 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
GitHub PoC
CVE-2021-43617 bypass CRF
CVE-2021-4361719 nov 2021
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RIESGO
abrir
GitHub PoC1
CVE-2013-2171
CVE-2013-217118 nov 2021
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEAS
38RIESGO
abrir
GitHub PoC
cve-2020-35314,一个带phpcode的zip文件
CVE-2020-3531417 nov 2021
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, al
28RIESGO
abrir
GitHub PoC1
PoC for CVE-2017-17562 written in bash
CVE-2017-17562HIGHbajo ataque17 nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
GitHub PoC
Demonstration of CVE-2018-19571: GitLab SSRF CVE
CVE-2018-1957116 nov 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RIESGO
abrir
GitHub PoC
Confluence server webwork OGNL injection
CVE-2021-26086MEDIUMbajo ataque16 nov 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RIESGO
abrir
GitHub PoC34
CVE-2020-0787的简单回显
CVE-2020-0787HIGHbajo ataqueransomware16 nov 2021
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir
GitHub PoC117
Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera
CVE-2021-4045CRITICAL15 nov 2021
TP-LINK Tapo C200 remote code execution vulnerability
70RIESGO
abrir
GitHub PoC1
poc for CVE-2020-2555
CVE-2020-2555CRITICALbajo ataque15 nov 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
GitHub PoC3
Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701
CVE-2021-43616CRITICAL15 nov 2021
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in pack
48RIESGO
abrir
GitHub PoC
POC for CVE-2020-2883
CVE-2020-2883CRITICALbajo ataque15 nov 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
GitHub PoC
xMohamed0/CVE-2021-42013-ApacheRCE
CVE-2021-42013CRITICALbajo ataqueransomware14 nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
kubota/POC-CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware14 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
xMohamed0/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware14 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC8
Exploit for CVE-2017-17562 vulnerability, that allows RCE on GoAhead (< v3.6.5) if the CGI is enabled and a CGI program is dynamically linked.
CVE-2017-17562HIGHbajo ataque14 nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
anteriorpágina 348 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.