Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
VulnCheck XDB
client-side
CVE-2021-30632HIGHbajo ataque20 sep 2021
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RIESGO
abrir
GitHub PoC102
Modified code so that we don´t need to rely on CAB archives
CVE-2021-40444HIGHbajo ataqueransomware19 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2015-5119HIGHbajo ataque19 sep 2021
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2015-5122HIGHbajo ataque19 sep 2021
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RIESGO
abrir
GitHub PoC1
Converted Metasploit exploits for Adobe Flash vulnerabilities CVE-2015-3090, CVE-2015-3105, CVE-2015-5119, and CVE-2015-5122 to a Python3 script.
CVE-2015-309019 sep 2021
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALbajo ataqueransomware19 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Modifed ver of the original exploit to save some times on password reseting for unprivileged user
CVE-2021-2291119 sep 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC3
OMIGod / CVE-2021-38647 POC and Demo environment
CVE-2021-38647CRITICALbajo ataqueransomware19 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC11
Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit
CVE-2021-30860HIGHbajo ataque18 sep 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RIESGO
abrir
GitHub PoC3
[CVE-2021-26084] Confluence pre-auth RCE test script
CVE-2021-26084CRITICALbajo ataqueransomware18 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").
CVE-2021-38647CRITICALbajo ataqueransomware18 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Hikvision IP Camera Unauthenticated Command Injection
CVE-2021-36260CRITICALbajo ataque18 sep 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware18 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALbajo ataqueransomware18 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware17 sep 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC2
CVE-2021-40539 POC
CVE-2021-40539CRITICALbajo ataqueransomware17 sep 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RIESGO
abrir
Metasploit300
Wordpress BulletProof Security Backup Disclosure
CVE-2021-39327MEDIUM17 sep 2021
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RIESGO
abrir
Exploit-DB
WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass
CVE-2021-34646CRITICALwebappsphp17 sep 2021
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RIESGO
abrir
Metasploit600
ManageEngine ServiceDesk Plus CVE-2021-44077
CVE-2021-44077CRITICALbajo ataque16 sep 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RIESGO
abrir
GitHub PoC233
Proof on Concept Exploit for CVE-2021-38647 (OMIGOD)
CVE-2021-38647CRITICALbajo ataqueransomware16 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
A PoC exploit for CVE-2021-38647 RCE in OMI
CVE-2021-38647CRITICALbajo ataqueransomware16 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC20
OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team, specifically CVE-2021-38647.
CVE-2021-38647CRITICALbajo ataqueransomware16 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-38647CRITICALbajo ataqueransomware16 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALbajo ataqueransomware16 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC6
CVE-2021-2456
CVE-2021-2456CRITICAL16 sep 2021
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RIESGO
abrir
GitHub PoC9
quynhle7821/CVE-2021-2302
CVE-2021-2302CRITICAL16 sep 2021
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported
48RIESGO
abrir
GitHub PoC824
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
CVE-2021-40444HIGHbajo ataqueransomware15 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware15 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC10
CVE-2021-33766-poc
CVE-2021-33766HIGHbajo ataque15 sep 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RIESGO
abrir
GitHub PoC8
CVE-2021-38647 POC for RCE
CVE-2021-38647CRITICALbajo ataqueransomware15 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 654 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.