Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.316exploits catalogados
34.835CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC6
POC for CVE-2021-34429 - Eclipse Jetty 11.0.5 Sensitive File Disclosure
CVE-2021-34429MEDIUM03 nov 2021
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RIESGO
abrir
GitHub PoC48
Exploitation code for CVE-2021-40539
CVE-2021-40539CRITICALbajo ataqueransomware03 nov 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RIESGO
abrir
GitHub PoC
It is a simple tool to exploit local file include . vulnerabilities
CVE-2006-339203 nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
GitHub PoC
It is a simple tool to exploit local file include . vulnerabilities
CVE-2006-339203 nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
GitHub PoC5
Fuel CMS 1.4.1 - Remote Code Execution
CVE-2018-1676303 nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC4
Proof-of-Concept tool for CVE-2021-29156, an LDAP injection vulnerability in ForgeRock OpenAM v13.0.0.
CVE-2021-2915603 nov 2021
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacke
60RIESGO
abrir
GitHub PoC1
Exploit Apache 2.4.50(CVE-2021-42013)
CVE-2021-42013CRITICALbajo ataqueransomware03 nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
Test vulnerability of CVE-2020-3452
CVE-2020-3452HIGHbajo ataque03 nov 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC3
CVE-2021-22205-getshell
CVE-2021-22205CRITICALbajo ataqueransomware01 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC
MovableType XMLRPC - RCE
CVE-2021-2083701 nov 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RIESGO
abrir
GitHub PoC
Exploit and Demo system for CVE-2021-3156
CVE-2021-3156HIGHbajo ataque01 nov 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC13
CVE-2021-22205 RCE
CVE-2021-22205CRITICALbajo ataqueransomware31 oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC2
kienquoc102/CVE-2017-8225
CVE-2017-822530 oct 2021
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RIESGO
abrir
GitHub PoC
C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…
CVE-2021-26855CRITICALbajo ataqueransomware30 oct 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC23
CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用
CVE-2021-22205CRITICALbajo ataqueransomware30 oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC21
XMLRPC - RCE in MovableTypePoC
CVE-2021-2083730 oct 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RIESGO
abrir
GitHub PoC2
PoC in single line bash
CVE-2021-22205CRITICALbajo ataqueransomware30 oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC285
CVE-2021-22205& GitLab CE/EE RCE
CVE-2021-22205CRITICALbajo ataqueransomware29 oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC7
Gitlab CE/EE RCE 未授权远程代码执行漏洞 POC && EXP CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware29 oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC
Setup vulnerable enviornment
CVE-2021-41773HIGHbajo ataqueransomware29 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
scopion/CVE-2018-8947
CVE-2018-894729 oct 2021
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easi
28RIESGO
abrir
GitHub PoC
0xAgun/CVE-2019-18935-checker
CVE-2019-18935CRITICALbajo ataqueransomware29 oct 2021
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC
scopion/CVE-2020-10963
CVE-2020-1096329 oct 2021
FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution)
28RIESGO
abrir
GitHub PoC2
BabyTeam1024/CVE-2021-40438
CVE-2021-40438CRITICALbajo ataqueransomware28 oct 2021
mod_proxy SSRF
100RIESGO
abrir
GitHub PoC86
Pocsuite3 For CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware28 oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC9
An attempt to reproduce Microsoft MSHTML Remote Code Execution (RCE) Vulnerability and using Metasploit Framework.
CVE-2021-40444HIGHbajo ataqueransomware28 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC69
CVE-2021-22205 Unauthorized RCE
CVE-2021-22205CRITICALbajo ataqueransomware28 oct 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC1
批量扫描CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware28 oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC296
command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
CVE-2021-36260CRITICALbajo ataque27 oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
b1tg/CVE-2021-34486-exp
CVE-2021-34486HIGHbajo ataque27 oct 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RIESGO
abrir
anteriorpágina 350 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.