Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
VulnCheck XDB
local
CVE-2021-1675HIGHbajo ataqueransomware05 oct 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
CVE-2021-26085MEDIUMbajo ataqueransomwarewebappsjava05 oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware04 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Opensitoo/cve-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware04 oct 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC2
Exploit code for CVE-2007-2447 written in Python3.
CVE-2007-244703 oct 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC2
CVE-2018-15961 — ᴀᴅᴏʙᴇ ᴄᴏʟᴅғᴜsɪᴏɴ (ʀᴄᴇ)
CVE-2018-15961CRITICALbajo ataque03 oct 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALbajo ataqueransomware03 oct 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware03 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware03 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALbajo ataque03 oct 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
GitHub PoC7
Proof On Concept — Pulse Secure CVE-2021-22893
CVE-2021-22893CRITICALbajo ataqueransomware03 oct 2021
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo
90RIESGO
abrir
GitHub PoC11
CVE-2021-21972 – ᴠᴍᴡᴀʀᴇ ᴄʟɪᴇɴᴛ ᴜɴᴀᴜᴛʜᴏʀɪᴢᴇᴅ ᴄᴏᴅᴇ ɪɴᴊᴇᴄᴛɪᴏɴ (ʀᴄᴇ)
CVE-2021-21972CRITICALbajo ataqueransomware03 oct 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC9
H0j3n/CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware03 oct 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
puckiestyle/CVE-2021-3493
CVE-2021-3493HIGHbajo ataque02 oct 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC2
Exploit for CVE-2019-17662 (ThinVNC 1.0b1)
CVE-2019-1766202 oct 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir
GitHub PoC22
the metasploit script(POC/EXP) about CVE-2021-22005 VMware vCenter Server contains an arbitrary file upload vulnerability
CVE-2021-22005CRITICALbajo ataqueransomware02 oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
GitHub PoC
wdjcy/CVE-2021-26084
CVE-2021-26084CRITICALbajo ataqueransomware02 oct 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-34523CRITICALbajo ataqueransomware02 oct 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALbajo ataqueransomware02 oct 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
GitHub PoC16
POC for scanning ProxyShell(CVE-2021-34523,CVE-2021-34473,CVE-2021-31207)
CVE-2021-34523CRITICALbajo ataqueransomware02 oct 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
CVE-2021-41318webappsmultiple01 oct 2021
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RIESGO
abrir
GitHub PoC1
daletoniris/CVE-2021-22555-esc-priv
CVE-2021-22555HIGHbajo ataque01 oct 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
Metasploit600
ManageEngine ADAudit Plus Authenticated File Write RCE
CVE-2021-4284701 oct 2021
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
40RIESGO
abrir
GitHub PoC12
PoC for CVE-2021-3129 (Laravel)
CVE-2021-3129CRITICALbajo ataqueransomware01 oct 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
CloudMe CVE-2018-6892 POC
CVE-2018-689201 oct 2021
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
GitHub PoC1
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.
CVE-2019-1766201 oct 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34730CRITICAL30 sep 2021
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerability
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-35211CRITICALbajo ataqueransomware30 sep 2021
Serv-U Remote Memory Escape Vulnerability
100RIESGO
abrir
GitHub PoC12
Simple Serv-U CVE-2021-35211 PoC
CVE-2021-35211CRITICALbajo ataqueransomware30 sep 2021
Serv-U Remote Memory Escape Vulnerability
100RIESGO
abrir
GitHub PoC28
Cisco RV110w UPnP stack overflow
CVE-2021-34730CRITICAL30 sep 2021
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerability
53RIESGO
abrir
anteriorpágina 651 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.