Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC
JMousqueton/Detect-CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware27 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC
CVE-2015-3224
CVE-2015-322427 feb 2021
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
GitHub PoC28
Nmap script to check vulnerability CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware26 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC44
ZeusBox/CVE-2021-21017
CVE-2021-21017HIGHbajo ataque26 feb 2021
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
93RIESGO
abrir
GitHub PoC8
CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque25 feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC
A vulnerability scanner that detects CVE-2020-14883 vulnerabilities.
CVE-2020-14883HIGHbajo ataque25 feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC2
CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware25 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC1
L-pin/CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware25 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC28
VMware vCenter 未授权RCE(CVE-2021-21972)
CVE-2021-21972CRITICALbajo ataqueransomware25 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC33
CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware25 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC11
VMware vCenter Server远程代码执行漏洞 (CVE-2021-21972)批量检测脚本
CVE-2021-21972CRITICALbajo ataqueransomware25 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC1
A vulnerability scanner that detects CVE-2021-21972 vulnerabilities.
CVE-2021-21972CRITICALbajo ataqueransomware25 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC15
Nibbleblog 4.0.3 - Arbitrary File Upload (CVE-2015-6967)
CVE-2015-696725 feb 2021
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir
GitHub PoC54
alt3kx/CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware25 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC
A vulnerability scanner that detects CVE-2020-17519 vulnerabilities.
CVE-2020-17519CRITICALbajo ataque25 feb 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC8
yaunsky/CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware24 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC271
Proof of Concept Exploit for vCenter CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware24 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC137
QmF0c3UK/CVE-2021-21972-vCenter-6.5-7.0-RCE-POC
CVE-2021-21972CRITICALbajo ataqueransomware24 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC3
lsw29475/CVE-2019-17026
CVE-2019-17026HIGHbajo ataque24 feb 2021
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RIESGO
abrir
GitHub PoC500
CVE-2021-21972 Exploit
CVE-2021-21972CRITICALbajo ataqueransomware24 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC
oneoy/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque23 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC3
Python implementation of 'Username' map script' RCE Exploit for Samba 3.0.20 < 3.0.25rc3 (CVE-2007-2447).
CVE-2007-244722 feb 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC1
Nicoslo/Windows-Exploitation-Web-Server-Tomcat-8.5.39-CVE-2019-0232
CVE-2019-023221 feb 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC1
Nicoslo/Windows-exploitation-Apache-Tomcat-8.5.19-CVE-2019-0232-
CVE-2019-023220 feb 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC1
Nicoslo/Windows-exploitation-Rejetto-HTTP-File-Server-HFS-2.3.x-CVE-2014-6287
CVE-2014-6287CRITICALbajo ataque20 feb 2021
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC
roninAPT/CVE-2018-0802
CVE-2018-0802HIGHbajo ataque20 feb 2021
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
GitHub PoC
Full exploit code for CVE-2019-25024 an unauthenticated command injection flaw in OpenRepeater.
CVE-2019-2502419 feb 2021
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy
28RIESGO
abrir
GitHub PoC
Eternit7/CVE-2019-1458
CVE-2019-1458HIGHbajo ataqueransomware19 feb 2021
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC1
Nicoslo/Windows-exploitation-BadBlue-2.7-CVE-2007-6377
CVE-2007-637718 feb 2021
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RIESGO
abrir
GitHub PoC163
Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)
CVE-2021-3129CRITICALbajo ataqueransomware18 feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
anteriorpágina 378 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.