Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
13.937 exploits
GitHub PoC478
Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)
CVE-2021-40449HIGHbajo ataqueransomware16 oct 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
TIC4301 Project - CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware16 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
metehangenel/MSHTML-CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware15 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC4
The first vulnerability with the CVE identifier CVE-2021-41773 is a path traversal flaw that exists in Apache HTTP Server 2.4.49.
CVE-2021-41773HIGHbajo ataqueransomware15 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC9
apache httpd path traversal checker(CVE-2021-41773 / CVE-2021-42013)
CVE-2021-41773HIGHbajo ataqueransomware15 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
CVE-2020-25078账号密码信息泄露批量脚本Batch script of D-Link DCS series camera account password information disclosure
CVE-2020-25078HIGHbajo ataque15 oct 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir
GitHub PoC
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
CVE-2021-4207115 oct 2021
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RIESGO
abrir
GitHub PoC
My take on CVE-2021-30858 for ps4 8.xx
CVE-2021-30858HIGHbajo ataque14 oct 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, m
76RIESGO
abrir
GitHub PoC1
Testing CVE-2021-30858 Rev3
CVE-2021-30858HIGHbajo ataque14 oct 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, m
76RIESGO
abrir
GitHub PoC
zomy22/CVE-2020-16846-Saltstack-Salt-API
CVE-2020-16846CRITICALbajo ataque14 oct 2021
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RIESGO
abrir
GitHub PoC2
Docker container lab to play/learn with CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware14 oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
Docker container lab to play/learn with CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware14 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC8
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
CVE-2020-1077013 oct 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RIESGO
abrir
GitHub PoC61
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
CVE-2021-41773HIGHbajo ataqueransomware13 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Hasintha-98/Sudo-Vulnerability-Exploit-CVE-2019-14287
CVE-2019-1428713 oct 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC61
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
CVE-2020-17519CRITICALbajo ataque13 oct 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC2
musergi/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque13 oct 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
nxlog ubuntu CVE-2020-35488
CVE-2020-3548812 oct 2021
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RIESGO
abrir
GitHub PoC51
Windows Etw LPE
CVE-2021-34486HIGHbajo ataque12 oct 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC13
hoav18/CVE-2021-22941
CVE-2021-22941CRITICALbajo ataqueransomware12 oct 2021
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RIESGO
abrir
GitHub PoC1
critical: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) (CVE-2021-42013)
CVE-2021-41773HIGHbajo ataqueransomware12 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE
CVE-2021-41773HIGHbajo ataqueransomware11 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC4
CVE-2021-41773 Grabber
CVE-2021-41773HIGHbajo ataqueransomware11 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC188
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
CVE-2021-33044CRITICALbajo ataque11 oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC
rasyidfox/CVE-2019-18818
CVE-2019-1881811 oct 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
GitHub PoC8
dongpohezui/cve-2021-33045
CVE-2021-33045CRITICALbajo ataque11 oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC
CyberTuz/CVE-2019-15107_detection
CVE-2019-15107CRITICALbajo ataqueransomware10 oct 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC133
Exploit for CVE-2021-30807
CVE-2021-30807HIGHbajo ataque09 oct 2021
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS
76RIESGO
abrir
GitHub PoC
Murasame-nc/CVE-2020-0796-LPE-POC
CVE-2020-0796CRITICALbajo ataqueransomware09 oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC5
Remote Code Execution POC for CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware09 oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
anteriorpágina 354 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.