Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
VulnCheck XDB
initial-access
CVE-2021-35211CRITICALbajo ataqueransomware24 oct 2021
Serv-U Remote Memory Escape Vulnerability
100RIESGO
abrir
GitHub PoC
tiagob0b/CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware24 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
tiagob0b/CVE-2021-22005
CVE-2021-22005CRITICALbajo ataqueransomware24 oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
GitHub PoC7
PoC CVE-2021-42013 reverse shell Apache 2.4.50 with CGI
CVE-2021-42013CRITICALbajo ataqueransomware24 oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
Serv-U-FTP CVE-2021-35211 exploit
CVE-2021-35211CRITICALbajo ataqueransomware24 oct 2021
Serv-U Remote Memory Escape Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-40438CRITICALbajo ataqueransomware24 oct 2021
mod_proxy SSRF
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware23 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-41773HIGHbajo ataqueransomware23 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC2
cve-2021-41773.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.49
CVE-2021-41773HIGHbajo ataqueransomware23 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC2
Poc CVE-2021-42013 - Apache 2.4.50 without CGI
CVE-2021-42013CRITICALbajo ataqueransomware23 oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
Poc CVE-2021-41773 - Apache 2.4.49 with CGI enabled
CVE-2021-41773HIGHbajo ataqueransomware23 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
BabyTeam1024/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware22 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
scopion/CVE-2017-3241
CVE-2017-324122 oct 2021
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RIESGO
abrir
Exploit-DB
Jetty 9.4.37.v20210219 - Information Disclosure
CVE-2021-28164MEDIUMwebappsjava22 oct 2021
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RIESGO
abrir
Metasploit300
BillQuick Web Suite txtID SQLi
CVE-2021-42258CRITICALbajo ataqueransomware22 oct 2021
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution
95RIESGO
abrir
Metasploit300
Wordpress Plugin Catch Themes Demo Import RCE
CVE-2021-39352HIGH21 oct 2021
Catch Themes Demo Import <= 1.7 Admin+ Arbitrary File Upload
48RIESGO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHbajo ataqueransomware20 oct 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2021-3156 exploit
CVE-2021-3156HIGHbajo ataque20 oct 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC98
windows 10 14393 LPE
CVE-2021-40449HIGHbajo ataqueransomware20 oct 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
LayarKacaSiber/CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware20 oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
THIS IS NOT AN ORIGINAL EXPLOIT. THIS IS AN AUDITED VERSION FOR A THM BOX
CVE-2020-10915CRITICAL20 oct 2021
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
85RIESGO
abrir
GitHub PoC
LayarKacaSiber/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware20 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
Exploit-DB
SonicWall SMA 10.2.1.0-17sv - Password Reset
CVE-2021-20034webappshardware20 oct 2021
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal
45RIESGO
abrir
GitHub PoC1
Exploit CVE 2021 26084 Confluence
CVE-2021-26084CRITICALbajo ataqueransomware20 oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware20 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware20 oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC2
Just a simple CVE-2021-31166 exploit tool
CVE-2021-31166CRITICALbajo ataque20 oct 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-398019 oct 2021
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RIESGO
abrir
Exploit-DB
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24719webappsphp19 oct 2021
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21234HIGH19 oct 2021
Directory Traversal
61RIESGO
abrir
anteriorpágina 644 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.