Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2020-7247
CVE-2020-7247CRITICALbajo ataque
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Referência
CVE-2020-7247
CVE-2020-7247CRITICALbajo ataque
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Referência
CVE-2020-7247
CVE-2020-7247CRITICALbajo ataque
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Referência
CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
Referência
CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
Referência
CVE-2021-22555
CVE-2021-22555HIGHbajo ataque
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
Referência
CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
Referência
CVE-2021-22986
CVE-2021-22986CRITICALbajo ataqueransomware
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RIESGO
abrir
Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RIESGO
abrir
Referência
CVE-2021-27065
CVE-2021-27065HIGHbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2021-27065
CVE-2021-27065HIGHbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2021-27370
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
23RIESGO
abrir
Referência
CVE-2021-27520
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RIESGO
abrir
Referência
openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting
CVE-2021-27695webappsmultiple
Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbit
23RIESGO
abrir
Referência
In4Suit ERP 3.2.74.1370 - 'txtLoginId' SQL injection
CVE-2021-27828webappsmultiple
SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the a
28RIESGO
abrir
Referência
CVE-2021-27889
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
23RIESGO
abrir
Referência
CVE-2021-27928
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RIESGO
abrir
Referência
CVE-2021-28164
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RIESGO
abrir
Referência
CVE-2021-29440
Twig allowing dangerous PHP functions by default
53RIESGO
abrir
Referência
CVE-2021-30034
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
23RIESGO
abrir
Referência
CVE-2021-30039
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo
23RIESGO
abrir
Referência
CVE-2021-30042
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont
23RIESGO
abrir
Referência
CVE-2021-3018
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
43RIESGO
abrir
Referência
CVE-2021-31761
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's ru
35RIESGO
abrir
Referência
CVE-2021-32172
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RIESGO
abrir
Referência
CVE-2021-36260
CVE-2021-36260CRITICALbajo ataque
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
Referência
CVE-2021-36711
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
28RIESGO
abrir
Referência
CVE-2021-38759
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain a
28RIESGO
abrir
Referência
CVE-2021-39312
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RIESGO
abrir
anteriorpágina 546 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.