Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
GitHub PoC20
Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE
CVE-2021-41773HIGHbajo ataqueransomware06 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
Apache 2.4.49
CVE-2021-41773HIGHbajo ataqueransomware06 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC5
DirtyCow root privilege escalation (CVE-2016-5195)
CVE-2016-5195HIGHbajo ataque06 oct 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC7
CVE-2021-3625 - Sample exploits for Zephyr
CVE-2021-3625CRITICAL06 oct 2021
Buffer overflow in Zephyr USB DFU DNLOAD
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware06 oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC
hh-hunter/cve-2021-24499
CVE-2021-2449906 oct 2021
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1675HIGHbajo ataqueransomware05 oct 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit300
WordPress Plugin Perfect Survey 1.5.1 SQLi (Unauthenticated)
CVE-2021-2476205 oct 2021
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RIESGO
abrir
GitHub PoC38
CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
masahiro331/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC17
ZephrFish/CVE-2021-41773-PoC
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC52
iilegacyyii/PoC-CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC9
Path traversal in Apache HTTP Server 2.4.49 (CVE-2021-41773)
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC6
Poc.py
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC8
CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
bypass all stages of the password reset flow
CVE-2021-27651CRITICAL05 oct 2021
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RIESGO
abrir
GitHub PoC1
Working PowerShell POC
CVE-2021-1675HIGHbajo ataqueransomware05 oct 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC13
Exploitation of CVE-2021-41773 a Directory Traversal in Apache 2.4.49.
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware05 oct 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
Exploit-DB
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
CVE-2021-26085MEDIUMbajo ataqueransomwarewebappsjava05 oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RIESGO
abrir
GitHub PoC13
Atlassian Confluence Server 7.5.1 Pre-Authorization Arbitrary File Read vulnerability (CVE-2021-26085)
CVE-2021-26085MEDIUMbajo ataqueransomware05 oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-26085MEDIUMbajo ataqueransomware05 oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware05 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
POC: CVE-2019-12840 (Authenticated RCE - Webmin Package Updates)
CVE-2019-1284005 oct 2021
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
GitHub PoC
Exploit para CVE-2019-15107 (Webmin 1.890-1.920) sin credenciales RCE escrito en PYTHON.
CVE-2019-15107CRITICALbajo ataqueransomware05 oct 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC1
The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
CVE-2021-2456305 oct 2021
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RIESGO
abrir
anteriorpágina 650 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.