Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.866exploits catalogados
35.812CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC
racoon-rac/CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC8
PoC of FortiWAN auth bypass (https://www.fortiguard.com/psirt/FG-IR-21-048)
CVE-2021-26102CRITICAL09 dic 2021
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remot
53RIESGO
abrir
GitHub PoC1
CVE-2021-27928-POC
CVE-2021-2792809 dic 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RIESGO
abrir
Exploit-DB
Student Management System 1.0 - SQLi Authentication Bypass
CVE-2020-23935webappsphp09 dic 2021
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-120709 dic 2021
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RIESGO
abrir
GitHub PoC89
Apache Log4j 远程代码执行
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
Simple program for exploit grafana
CVE-2021-43798HIGHbajo ataque09 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC9
Grafana-POC任意文件读取漏洞(CVE-2021-43798)
CVE-2021-43798HIGHbajo ataque09 dic 2021
Grafana path traversal
100RIESGO
abrir
Exploit-DB
Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
CVE-2021-43798HIGHbajo ataquewebappsmultiple09 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC19
Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC17
Exploit iDRAC 7 & 8 firmware < 2.52.52.52
CVE-2018-120709 dic 2021
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RIESGO
abrir
Exploit-DB
Raspberry Pi 5.10 - Default Credentials
CVE-2021-38759remotelinux09 dic 2021
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain a
28RIESGO
abrir
Metasploit600
UniFi Network Application Unauthenticated JNDI Injection RCE (via Log4Shell)
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit600
Microsoft Exchange Server ChainedSerializationBinder RCE
CVE-2021-42321HIGHbajo ataqueransomware09 dic 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Log4Shell HTTP Header Injection
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit600
Microsoft Exchange Server ChainedSerializationBinder RCE
CVE-2022-23277HIGH09 dic 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
48RIESGO
abrir
Metasploit300
Log4Shell HTTP Scanner
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit300
Log4Shell HTTP Scanner
CVE-2021-45046CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
Metasploit600
VMware vCenter Server Unauthenticated JNDI Injection RCE (via Log4Shell)
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
CVE-2021-43798Exp多线程批量验证脚本
CVE-2021-43798HIGHbajo ataque09 dic 2021
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-21972CRITICALbajo ataqueransomware09 dic 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
update to Daniele Scanu's SQL Injection Exploit - CVE-2019-9053
CVE-2019-905309 dic 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1960908 dic 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque08 dic 2021
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque08 dic 2021
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque08 dic 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALbajo ataqueransomware08 dic 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
GitHub PoC
Grafana File-Read Vuln
CVE-2021-43798HIGHbajo ataque08 dic 2021
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44077CRITICALbajo ataque08 dic 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RIESGO
abrir
anteriorpágina 634 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.