Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
13.937 exploits
GitHub PoC1
Remote Command Execution through Unvalidated File Upload in SeedDMS versions <5.1.11
CVE-2019-1274424 jun 2021
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a differe
28RIESGO
abrir
GitHub PoC12
GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425)
CVE-2021-21425CRITICAL24 jun 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
GitHub PoC
Badbird3/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware24 jun 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC11
Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.
CVE-2020-1472MEDIUMbajo ataqueransomware23 jun 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
m3terpreter/CVE-2016-4437
CVE-2016-4437CRITICALbajo ataque22 jun 2021
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
GitHub PoC
pywc/CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware21 jun 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
POC-CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware19 jun 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC2
PoC exploit for CVE-2020-7247 OpenSMTPD 6.4.0 < 6.6.1 Remote Code Execution
CVE-2020-7247CRITICALbajo ataque19 jun 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC126
Privilege escalation with polkit - CVE-2021-3560
CVE-2021-3560HIGHbajo ataque19 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
h3x0v3rl0rd/CVE-2019-14287
CVE-2019-1428717 jun 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
spyx/cve-2019-17240
CVE-2019-17240LOW15 jun 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC
Polkit - Local Privilege Escalation (CVE-2021-3560)
CVE-2021-3560HIGHbajo ataque15 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC8
CVE-2018-19422 Authenticated Remote Code Execution
CVE-2018-1942214 jun 2021
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir
GitHub PoC
sujaygr8/CVE-2020-3187
CVE-2020-3187CRITICAL14 jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RIESGO
abrir
GitHub PoC124
secnigma/CVE-2021-3560-Polkit-Privilege-Esclation
CVE-2021-3560HIGHbajo ataque14 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
polkit exploit script v1.0
CVE-2021-3560HIGHbajo ataque14 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC19
wpDiscuz 7.0.4 Remote Code Execution
CVE-2020-24186CRITICAL13 jun 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir
GitHub PoC2
ZeroShell 3.9.0 Remote Command Injection
CVE-2019-1272513 jun 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC1
CVE-2021–22201 Arbitrary file read on Gitlab
CVE-2021-22201CRITICAL13 jun 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file
48RIESGO
abrir
GitHub PoC40
a reliable C based exploit and writeup for CVE-2021-3560.
CVE-2021-3560HIGHbajo ataque12 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC5
Automatic Explotation PoC for Polkit CVE-2021-3560
CVE-2021-3560HIGHbajo ataque11 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC82
CVE-2021-3560 Local PrivEsc Exploit
CVE-2021-3560HIGHbajo ataque11 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC8
Python3 POC for CVE 2020-11060
CVE-2020-11060HIGH11 jun 2021
Remote Code Execution in GLPI
46RIESGO
abrir
GitHub PoC2
CrackerCat/CVE-2020-1020-Exploit
CVE-2020-1020HIGHbajo ataque10 jun 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RIESGO
abrir
GitHub PoC
sujaygr8/CVE-2020-3452
CVE-2020-3452HIGHbajo ataque10 jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC10
freeide2017/CVE-2021-33739-POC
CVE-2021-33739HIGHbajo ataque09 jun 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
CVE-2017-9554 Exploit Tool
CVE-2017-955408 jun 2021
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
GitHub PoC4
kienquoc102/CVE-2018-9995-2
CVE-2018-999507 jun 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC7
suprise4u/CVE-2019-1388
CVE-2019-1388HIGHbajo ataqueransomware07 jun 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC
Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240
CVE-2019-17240LOW07 jun 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
anteriorpágina 368 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.