Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
GitHub PoC10
C# PrintNightmare (CVE-2021-1675)
CVE-2021-1675HIGHbajo ataqueransomware26 sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC209
Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)
CVE-2021-1675HIGHbajo ataqueransomware26 sep 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
AmesianX/CVE-2021-21220
CVE-2021-21220HIGHbajo ataque26 sep 2021
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
98RIESGO
abrir
GitHub PoC1
Python script to obtain RCE on Mantis Bug Tracker prior to version 1.2.x Check CVE-2008-4687 for additional information
CVE-2008-468725 sep 2021
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-22005CRITICALbajo ataqueransomware25 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
GitHub PoC17
CVE-2021-3156 - sudo exploit for ubuntu 18.04 & 20.04
CVE-2021-3156HIGHbajo ataque25 sep 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC13
CVE-2021-22005批量验证python脚本
CVE-2021-22005CRITICALbajo ataqueransomware25 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
GitHub PoC
CVE-2021-22005
CVE-2021-22005CRITICALbajo ataqueransomware24 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
GitHub PoC1
CVE-2021-38647 is an unauthenticated RCE vulnerability effecting the OMI agent as root.
CVE-2021-38647CRITICALbajo ataqueransomware24 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALbajo ataqueransomware24 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Windows Kernel Registry Elevation of Privilege Vulnerability
CVE-2018-841024 sep 2021
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RIESGO
abrir
GitHub PoC1
BeneficialCode/CVE-2021-1732
CVE-2021-1732HIGHbajo ataqueransomware24 sep 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
CVE 2021 40444 Windows Exploit services.dll
CVE-2021-40444HIGHbajo ataqueransomware24 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC5
CVE-2021-33739 PoC Analysis
CVE-2021-33739HIGHbajo ataque24 sep 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware24 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-33739HIGHbajo ataque24 sep 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC1
pisut4152/Sigma-Rule-for-CVE-2021-22005-scanning-activity
CVE-2021-22005CRITICALbajo ataqueransomware23 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
GitHub PoC8
1ZRR4H/CVE-2021-22005
CVE-2021-22005CRITICALbajo ataqueransomware23 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
Exploit-DB
WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF)
CVE-2021-24272webappsphp23 sep 2021
Fitness Calculators < 1.9.6 - Cross-Site Request Forgery to Cross-Site Scripting (XSS)
23RIESGO
abrir
Metasploit600
Microsoft Office Word Malicious MSHTML RCE
CVE-2021-40444HIGHbajo ataqueransomware23 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Gurock Testrail 7.2.0.3014 - 'files.md5' Improper Access Control
CVE-2021-40875webappsmultiple23 sep 2021
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RIESGO
abrir
Exploit-DB
WordPress Plugin Advanced Order Export For WooCommerce 3.1.7 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24169webappsphp23 sep 2021
Advanced Order Export For WooCommerce < 3.1.8 - Reflected Cross-Site Scripting (XSS)
43RIESGO
abrir
Exploit-DB
OpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE)
CVE-2019-13358webappsphp22 sep 2021
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying opera
28RIESGO
abrir
Exploit-DB
Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)
CVE-2021-40868webappsmultiple22 sep 2021
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
38RIESGO
abrir
GitHub PoC
https://github.com/corelight/CVE-2021-38647 without the bloat
CVE-2021-38647CRITICALbajo ataqueransomware22 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit0
VMware vCenter vScalation Priv Esc
CVE-2021-2201521 sep 2021
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and
18RIESGO
abrir
Metasploit600
VMware vCenter Server Analytics (CEIP) Service File Upload
CVE-2021-22005CRITICALbajo ataqueransomware21 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-30632HIGHbajo ataque20 sep 2021
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RIESGO
abrir
GitHub PoC68
CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD
CVE-2021-38647CRITICALbajo ataqueransomware20 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALbajo ataqueransomware20 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 653 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.