Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
Metasploit300
WordPress WPS Hide Login Login Page Revealer
CVE-2021-2491727 oct 2021
WPS Hide Login < 1.9.1 - Protection Bypass with Referer-Header
40RIESGO
abrir
GitHub PoC27
cve-2021-42013.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.50
CVE-2021-42013CRITICALbajo ataqueransomware27 oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
rafaelcaria/drupalgeddon2-CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware27 oct 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC21
VMware vCenter Server任意文件上传漏洞 / Code By:Jun_sheng
CVE-2021-22005CRITICALbajo ataqueransomware27 oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
Metasploit600
Zimbra zmslapd arbitrary module load
CVE-2022-3739327 oct 2021
Zimbra zmslapd arbitrary module load
18RIESGO
abrir
GitHub PoC298
command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
CVE-2021-36260CRITICALbajo ataque27 oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware27 oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALbajo ataqueransomware27 oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque27 oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware27 oct 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
b1tg/CVE-2021-34486-exp
CVE-2021-34486HIGHbajo ataque27 oct 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHbajo ataque27 oct 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC7
CVE-2021-26084,Atlassian Confluence OGNL注入漏洞
CVE-2021-26084CRITICALbajo ataqueransomware26 oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware26 oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC11
Remote Code Execution exploit for Apache servers. Affected versions: Apache 2.4.49, Apache 2.4.50
CVE-2021-41773HIGHbajo ataqueransomware26 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
MazX0p/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware25 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC45
LPE exploit for a UAF in Windows (CVE-2021-40449).
CVE-2021-40449HIGHbajo ataqueransomware25 oct 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
Apache Storm Nimbus getTopologyHistory Unauthenticated Command Execution
CVE-2021-3829425 oct 2021
Shell Command Injection Vulnerability in Nimbus Thrift Server
40RIESGO
abrir
GitHub PoC
Script fo testing CVE-2000-0649 for Apache and MS IIS servers
CVE-2000-064925 oct 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RIESGO
abrir
Exploit-DB
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
CVE-2021-42013CRITICALbajo ataqueransomwarewebappsmultiple25 oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
A automatic scanner to apache 2.4.49
CVE-2021-41773HIGHbajo ataqueransomware25 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware25 oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
Exploit-DB
Hikvision Web Server Build 210702 - Command Injection
CVE-2021-36260CRITICALbajo ataquewebappshardware25 oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC1
confluence远程代码执行RCE / Code By:Jun_sheng
CVE-2021-26084CRITICALbajo ataqueransomware25 oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC18
PoC for the CVE-2021-20837 : RCE in MovableType
CVE-2021-2083725 oct 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
CVE-2018-12613webappsphp25 oct 2021
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2083725 oct 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RIESGO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHbajo ataqueransomware25 oct 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24444webappsphp25 oct 2021
TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-40438CRITICALbajo ataqueransomware24 oct 2021
mod_proxy SSRF
100RIESGO
abrir
anteriorpágina 643 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.