Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
82.419 exploits
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALbajo ataque21 dic 2023
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2022-21882HIGHbajo ataqueransomware21 dic 2023
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2020-25078HIGHbajo ataque21 dic 2023
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2022-0492HIGHbajo ataque21 dic 2023
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2016-4657HIGHbajo ataque21 dic 2023
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHbajo ataqueransomware21 dic 2023
Active Directory Domain Services Elevation of Privilege Vulnerability
93RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2018-4878HIGHbajo ataqueransomware21 dic 2023
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir ↗
GitHub PoC★ 1
Directory Traversal and Arbitrary File Read on Grafana
CVE-2021-43798HIGHbajo ataque21 dic 2023
Grafana path traversal
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-1207—21 dic 2023
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RIESGO
abrir ↗
VulnCheck XDB
info-leak
CVE-2017-11882HIGHbajo ataqueransomware21 dic 2023
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware21 dic 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-31728—21 dic 2023
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to
23RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2021-26828HIGHbajo ataque21 dic 2023
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware21 dic 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALbajo ataqueransomware21 dic 2023
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2019-15107CRITICALbajo ataqueransomware21 dic 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALbajo ataqueransomware21 dic 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2001-0680—21 dic 2023
Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse direc
23RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware21 dic 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2019-5736—21 dic 2023
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALbajo ataqueransomware21 dic 2023
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-0230—21 dic 2023
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-22214MEDIUM21 dic 2023
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware21 dic 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-16763—21 dic 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware21 dic 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-22536CRITICALbajo ataque21 dic 2023
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware21 dic 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-0230—21 dic 2023
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware21 dic 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗
← anteriorpágina 515 / 2748siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.