Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
htmly 2.8.0 - 'description' Stored Cross-Site Scripting (XSS)
CVE-2021-30637webappsmultiple15 abr 2021
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
23RIESGO
abrir
Exploit-DB
jQuery 1.2 - Cross-Site Scripting (XSS)
CVE-2020-11022MEDIUMwebappsmultiple14 abr 2021
jQuery has a potential XSS vulnerability
55RIESGO
abrir
Exploit-DB
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE
CVE-2021-29003webappshardware14 abr 2021
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RIESGO
abrir
Exploit-DB
CITSmart ITSM 9.1.2.22 - LDAP Injection
CVE-2020-35775webappsjava14 abr 2021
CITSmart before 9.1.2.23 allows LDAP Injection.
28RIESGO
abrir
Exploit-DB
CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
CVE-2021-28142webappsjava14 abr 2021
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
23RIESGO
abrir
Exploit-DB
MariaDB 10.2 - 'wsrep_provider' OS Command Execution
CVE-2021-27928locallinux14 abr 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RIESGO
abrir
Exploit-DB
jQuery 1.0.3 - Cross-Site Scripting (XSS)
CVE-2020-11023MEDIUMbajo ataquewebappsmultiple14 abr 2021
Potential XSS vulnerability in jQuery
85RIESGO
abrir
Exploit-DB
ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow
CVE-2020-29238webappsmultiple13 abr 2021
An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensi
28RIESGO
abrir
Exploit-DBVexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-2523remoteunix12 abr 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
Exploit-DB
PrestaShop 1.7.6.7 - 'location' Blind Sql Injection
CVE-2020-15160webappsphp09 abr 2021
Blind SQL Injection in PrestaShop
28RIESGO
abrir
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
CVE-2020-12351remotelinux08 abr 2021
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RIESGO
abrir
Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
CVE-2021-30147webappsmultiple08 abr 2021
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RIESGO
abrir
Exploit-DB
Composr 10.0.36 - Remote Code Execution
CVE-2021-30149webappsphp08 abr 2021
Composr 10.0.36 allows upload and execution of PHP files.
28RIESGO
abrir
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
CVE-2020-12352remotelinux08 abr 2021
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RIESGO
abrir
Exploit-DB
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
CVE-2020-5377CRITICALwebappswindows07 abr 2021
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RIESGO
abrir
Exploit-DB
Composr CMS 10.0.36 - Cross Site Scripting
CVE-2021-30150webappsphp07 abr 2021
Composr 10.0.36 allows XSS in an XML script.
23RIESGO
abrir
Exploit-DB
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
CVE-2020-14166webappsmultiple07 abr 2021
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RIESGO
abrir
Exploit-DB
Google Chrome 81.0.4044 V8 - Remote Code Execution
CVE-2020-6507remotemultiple06 abr 2021
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
28RIESGO
abrir
Exploit-DB
Google Chrome 86.0.4240 V8 - Remote Code Execution
CVE-2020-16040remotemultiple06 abr 2021
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir
Exploit-DB
F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated)
CVE-2021-22986CRITICALbajo ataqueransomwarewebappshardware02 abr 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
Exploit-DB
SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
CVE-2017-15950webappswindows29 mar 2021
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RIESGO
abrir
Exploit-DB
Concrete5 8.5.4 - 'name' Stored XSS
CVE-2021-3111webappsphp29 mar 2021
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.p
23RIESGO
abrir
Exploit-DB
Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
CVE-2012-6708webappshardware25 mar 2021
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RIESGO
abrir
Exploit-DB
Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
CVE-2020-14209webappsphp25 mar 2021
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio
28RIESGO
abrir
Exploit-DBVexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
CVE-2018-14009webappsmultiple23 mar 2021
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RIESGO
abrir
Exploit-DB
MyBB 1.8.25 - Poll Vote Count SQL Injection
CVE-2021-27946webappsphp23 mar 2021
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RIESGO
abrir
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27890webappsphp22 mar 2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RIESGO
abrir
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27889webappsphp22 mar 2021
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
23RIESGO
abrir
Exploit-DB
WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
CVE-2017-1000170webappsphp22 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RIESGO
abrir
Exploit-DB
LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
CVE-2019-12962webappsphp19 mar 2021
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
38RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.