Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
VulnCheck XDB
initial-access
CVE-2019-398019 oct 2021
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21234HIGH19 oct 2021
Directory Traversal
61RIESGO
abrir
Exploit-DB
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24719webappsphp19 oct 2021
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RIESGO
abrir
Exploit-DB
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
CVE-2020-11738HIGHbajo ataquewebappsphp18 oct 2021
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RIESGO
abrir
GitHub PoC4
xiaojiangxl/CVE-2021-40438
CVE-2021-40438CRITICALbajo ataqueransomware18 oct 2021
mod_proxy SSRF
100RIESGO
abrir
Exploit-DB
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
CVE-2021-41382webappsmultiple18 oct 2021
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RIESGO
abrir
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
CVE-2018-16060webappshardware18 oct 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listi
28RIESGO
abrir
GitHub PoC1
Lab setup for CVE-2021-41773 (Apache httpd 2.4.49) and CVE-2021-42013 (Apache httpd 2.4.50).
CVE-2021-41773HIGHbajo ataqueransomware18 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC17
CVE-2021-36260
CVE-2021-36260CRITICALbajo ataque18 oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
CVE-2018-16061webappshardware18 oct 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque18 oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC3
Dahua IPC/VTH/VTO devices auth bypass exploit
CVE-2021-33044CRITICALbajo ataque18 oct 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC1
Exploit For CVE-2019-17662
CVE-2019-1766218 oct 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware17 oct 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC11
Scanner for CVE-2022-22948 an Information Disclosure in VMWare vCenter
CVE-2022-22948MEDIUMbajo ataque17 oct 2021
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RIESGO
abrir
GitHub PoC35
Little thing put together quickly to demonstrate this CVE
CVE-2020-11022MEDIUM16 oct 2021
jQuery has a potential XSS vulnerability
55RIESGO
abrir
GitHub PoC478
Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)
CVE-2021-40449HIGHbajo ataqueransomware16 oct 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
TIC4301 Project - CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware16 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
Simple honeypot for CVE-2021-41773 vulnerability
CVE-2021-41773HIGHbajo ataqueransomware16 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALbajo ataque16 oct 2021
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-11022MEDIUM16 oct 2021
jQuery has a potential XSS vulnerability
55RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque16 oct 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHbajo ataqueransomware16 oct 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-25078HIGHbajo ataque15 oct 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware15 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC5
The first vulnerability with the CVE identifier CVE-2021-41773 is a path traversal flaw that exists in Apache HTTP Server 2.4.49.
CVE-2021-41773HIGHbajo ataqueransomware15 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
CVE-2020-25078账号密码信息泄露批量脚本Batch script of D-Link DCS series camera account password information disclosure
CVE-2020-25078HIGHbajo ataque15 oct 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir
GitHub PoC
metehangenel/MSHTML-CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware15 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
CVE-2021-4207115 oct 2021
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RIESGO
abrir
Exploit-DB
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
CVE-2021-41878webappsphp15 oct 2021
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RIESGO
abrir
anteriorpágina 645 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.