Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
GitHub PoC
漏洞复现与poc收集,CVE-2021-21975,cve-2021-22005,CVE-2021-26295,VMware vCenter任意文件读取
CVE-2021-21975HIGHbajo ataqueransomware29 sep 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
GitHub PoC5
This docx exploit uses res files inside Microsoft .docx file to execute malicious files. This exploit is related to CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware29 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable Samba versions, for which there is no fix. The newest Samba models, including the models 4.6.x before 4.6.4, 4.5.x before 4.5.10 and 3.5.0 before 4.4.13, was impacted by this error. May 24, 2017, Samba released version 4.6.4, which fixes a serious remote code execution vulnerability, vulnerability number CVE-2017-7494, which affected Samba 3.5.0 onwards. Vulnerability number: CVE-2017-7494 Severity Rating: High Affected software: • Samba Version < 4.6.4 • Samba Version < 4.5.10 • Samba Version < 4.4.14 Unaffected software: • Samba Version = 4.6.4 • Samba Version = 4.5.10 • Samba Version = 4.4.14
CVE-2017-7494CRITICALbajo ataqueransomware29 sep 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC
CVE-2021-25162
CVE-2021-2516229 sep 2021
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
28RIESGO
abrir
Exploit-DB
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24287webappsphp29 sep 2021
Select All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)
43RIESGO
abrir
Exploit-DB
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
CVE-2021-24286webappsphp29 sep 2021
Redirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
43RIESGO
abrir
Exploit-DB
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24276webappsphp28 sep 2021
Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
43RIESGO
abrir
GitHub PoC37
rwincey/CVE-2021-22005
CVE-2021-22005CRITICALbajo ataqueransomware28 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
Exploit-DB
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24610webappsphp28 sep 2021
TranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALbajo ataqueransomware28 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque28 sep 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24275webappsphp28 sep 2021
Popup by Supsystic < 1.10.5 - Reflected Cross-Site scripting (XSS)
43RIESGO
abrir
GitHub PoC14
CrackerCat/CVE-2021-30632
CVE-2021-30632HIGHbajo ataque28 sep 2021
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RIESGO
abrir
Exploit-DB
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24274webappsphp28 sep 2021
Ultimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site scripting (XSS)
43RIESGO
abrir
GitHub PoC19
Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166
CVE-2021-31166CRITICALbajo ataque27 sep 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676327 sep 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC2
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
CVE-2018-1676327 sep 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC3
CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware27 sep 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC
Sudo heap-based buffer overflow privilege escalation commands and mitigations.
CVE-2021-3156HIGHbajo ataque27 sep 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC1
CVE-2021-22005_PoC
CVE-2021-22005CRITICALbajo ataqueransomware27 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
Exploit-DB
XAMPP 7.4.3 - Local Privilege Escalation
CVE-2020-11107localwindows27 sep 2021
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALbajo ataqueransomware27 sep 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1675HIGHbajo ataqueransomware27 sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-1675HIGHbajo ataqueransomware27 sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALbajo ataqueransomware26 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-1675HIGHbajo ataqueransomware26 sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Quick and dirty CVE-2021-38647 (Omigod) exploit written in Go.
CVE-2021-38647CRITICALbajo ataqueransomware26 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1675HIGHbajo ataqueransomware26 sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALbajo ataqueransomware26 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-34527HIGHbajo ataqueransomware26 sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 652 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.