Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC8
Exploit for CVE-2017-17562 vulnerability, that allows RCE on GoAhead (< v3.6.5) if the CGI is enabled and a CGI program is dynamically linked.
CVE-2017-17562HIGHbajo ataque14 nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
GitHub PoC
xMohamed0/CVE-2021-21315-POC
CVE-2021-21315HIGHbajo ataque14 nov 2021
Command Injection Vulnerability
100RIESGO
abrir
GitHub PoC
Python script to exploit webmin vulnerability cve-2006-3392
CVE-2006-339213 nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
GitHub PoC
CVE-2021-3560 (Polkit - Local Privilege Escalation)
CVE-2021-3560HIGHbajo ataque12 nov 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC1
Реализация использования уязвимости Moodle CVE-2014-3544.
CVE-2014-354412 nov 2021
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before
23RIESGO
abrir
GitHub PoC1
CppXL/cve-2021-40449-poc
CVE-2021-40449HIGHbajo ataqueransomware12 nov 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Ce programme permet de détecter une faille RCE sur les serveurs Apache 2.4.49 et Apache 2.4.50
CVE-2021-41773HIGHbajo ataqueransomware11 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC237
GitLab CE/EE Preauth RCE using ExifTool
CVE-2021-22205CRITICALbajo ataqueransomware11 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC
Dockerized Proof-of-Concept of CVE-2021-40438 in Apache 2.4.48.
CVE-2021-40438CRITICALbajo ataqueransomware11 nov 2021
mod_proxy SSRF
100RIESGO
abrir
GitHub PoC2
On the 11/11/21 the apache 2.4.49-2.4.50 remote command execution POC has been published online and this is a loader so that you can mass exploit servers using this.
CVE-2021-41773HIGHbajo ataqueransomware11 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
rust noob tried write easy exploit code with rust lang
CVE-2021-21315HIGHbajo ataque10 nov 2021
Command Injection Vulnerability
100RIESGO
abrir
GitHub PoC
bu1xuan2/CVE-2018-15961
CVE-2018-15961CRITICALbajo ataque10 nov 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
GitHub PoC1
This Metasploit module exploits an unauthenticated remote code execution vulnerability which exists in Apache version 2.4.49 (CVE-2021-41773). If files outside of the document root are not protected by ‘require all denied’ and CGI has been explicitly enabled, it can be used to execute arbitrary commands. This vulnerability has been reintroduced in the Apache 2.4.50 fix (CVE-2021-42013).
CVE-2021-41773HIGHbajo ataqueransomware09 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC3
VMWARE VCENTER SERVER VIRTUAL SAN HEALTH CHECK PLUG-IN RCE (CVE-2021-21985)
CVE-2021-21985CRITICALbajo ataqueransomware09 nov 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
GitHub PoC18
A Zeek package to detect CVE-2021-42292, a Microsoft Excel local privilege escalation exploit.
CVE-2021-42292HIGHbajo ataque09 nov 2021
Microsoft Excel Security Feature Bypass Vulnerability
83RIESGO
abrir
GitHub PoC6
faisalfs10x/GitLab-CVE-2021-22205-scanner
CVE-2021-22205CRITICALbajo ataqueransomware09 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC1
Contains the offensive (exploit and auxiliary) modules for the CVE-2021-40444.
CVE-2021-40444HIGHbajo ataqueransomware08 nov 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC16
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252307 nov 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC52
Exploit for CVE-2021-40449
CVE-2021-40449HIGHbajo ataqueransomware07 nov 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC29
A sample POC for CVE-2021-30657 affecting MacOS
CVE-2021-30657MEDIUMbajo ataque07 nov 2021
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2
90RIESGO
abrir
GitHub PoC
JWT Exploit
CVE-2018-011406 nov 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC
mmeza-developer/CVE-2019-5420-RCE
CVE-2019-542006 nov 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
GitHub PoC3
Exploit for GitLab CVE-2021-22205 Unauthenticated Remote Code Execution
CVE-2021-22205CRITICALbajo ataqueransomware05 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC
hh-hunter/cve-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware05 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC4
Pickle Serialization Remote Code Execution - Memcached Poisoning
CVE-2021-33026CRITICAL05 nov 2021
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e
48RIESGO
abrir
GitHub PoC
CVE-2021-22205& GitLab CE/EE RCE
CVE-2021-22205CRITICALbajo ataqueransomware04 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC6
Some docker images to play with CVE-2021-41773 and CVE-2021-42013
CVE-2021-41773HIGHbajo ataqueransomware04 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
zkhalidul/GrabberWP-CVE-2017-5487
CVE-2017-548704 nov 2021
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
GitHub PoC2
Modification of gitlab exploit anything under 13.10
CVE-2021-22204MEDIUMbajo ataque04 nov 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC
It is a simple tool to exploit local file include . vulnerabilities
CVE-2006-339203 nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
anteriorpágina 349 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.