Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.866exploits catalogados
35.812CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC
POC for CVE-2020-2883
CVE-2020-2883CRITICALbajo ataque15 nov 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALbajo ataque15 nov 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL15 nov 2021
TP-LINK Tapo C200 remote code execution vulnerability
70RIESGO
abrir
Exploit-DB
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
CVE-2021-24664webappsphp15 nov 2021
WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
23RIESGO
abrir
GitHub PoC3
Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701
CVE-2021-43616CRITICAL15 nov 2021
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in pack
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALbajo ataque15 nov 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
Exploit-DB
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
CVE-2021-43617webappsphp15 nov 2021
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALbajo ataqueransomware15 nov 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC1
xMohamed0/CVE-2020-5504-phpMyAdmin
CVE-2020-550414 nov 2021
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RIESGO
abrir
GitHub PoC
xMohamed0/CVE-2021-21315-POC
CVE-2021-21315HIGHbajo ataque14 nov 2021
Command Injection Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-17562HIGHbajo ataque14 nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
GitHub PoC
xMohamed0/CVE-2021-42013-ApacheRCE
CVE-2021-42013CRITICALbajo ataqueransomware14 nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
kubota/POC-CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware14 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
xMohamed0/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware14 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC8
Exploit for CVE-2017-17562 vulnerability, that allows RCE on GoAhead (< v3.6.5) if the CGI is enabled and a CGI program is dynamically linked.
CVE-2017-17562HIGHbajo ataque14 nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
GitHub PoC
Python script to exploit webmin vulnerability cve-2006-3392
CVE-2006-339213 nov 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-22205CRITICALbajo ataqueransomware13 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALbajo ataque13 nov 2021
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC1
CppXL/cve-2021-40449-poc
CVE-2021-40449HIGHbajo ataqueransomware12 nov 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
Реализация использования уязвимости Moodle CVE-2014-3544.
CVE-2014-354412 nov 2021
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before
23RIESGO
abrir
GitHub PoC
CVE-2021-3560 (Polkit - Local Privilege Escalation)
CVE-2021-3560HIGHbajo ataque12 nov 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
Ce programme permet de détecter une faille RCE sur les serveurs Apache 2.4.49 et Apache 2.4.50
CVE-2021-41773HIGHbajo ataqueransomware11 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC237
GitLab CE/EE Preauth RCE using ExifTool
CVE-2021-22205CRITICALbajo ataqueransomware11 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-41773HIGHbajo ataqueransomwarewebappsmultiple11 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-42013CRITICALbajo ataqueransomwarewebappsmultiple11 nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Exploit-DB
FormaLMS 2.4.4 - Authentication Bypass
CVE-2021-43136webappsmultiple11 nov 2021
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALbajo ataqueransomware11 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC2
On the 11/11/21 the apache 2.4.49-2.4.50 remote command execution POC has been published online and this is a loader so that you can mass exploit servers using this.
CVE-2021-41773HIGHbajo ataqueransomware11 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Dockerized Proof-of-Concept of CVE-2021-40438 in Apache 2.4.48.
CVE-2021-40438CRITICALbajo ataqueransomware11 nov 2021
mod_proxy SSRF
100RIESGO
abrir
GitHub PoC
bu1xuan2/CVE-2018-15961
CVE-2018-15961CRITICALbajo ataque10 nov 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
anteriorpágina 639 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.