Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
GitHub PoC8
CVE-2021-38647 POC for RCE
CVE-2021-38647CRITICALbajo ataqueransomware15 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC5
CVE-2021-38647 AKA "OMIGOD" vulnerability in Windows OMI
CVE-2021-38647CRITICALbajo ataqueransomware15 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware15 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-33766HIGHbajo ataque15 sep 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware14 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft OMI Management Interface Authentication Bypass
CVE-2021-38648HIGHbajo ataque14 sep 2021
Open Management Infrastructure Elevation of Privilege Vulnerability
91RIESGO
abrir
Metasploit600
Microsoft OMI Management Interface Authentication Bypass
CVE-2021-38647CRITICALbajo ataqueransomware14 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
CVE-2018-15473 Exploit
CVE-2018-15473MEDIUM14 sep 2021
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
Malicious document builder for CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware14 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC19
k8gege/CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware14 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC8
CVE-2021-40875: Tools to Inspect Gurock Testrail Servers for Vulnerabilities related to CVE-2021-40875.
CVE-2021-4087513 sep 2021
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RIESGO
abrir
Exploit-DB
Facebook ParlAI 1.0.0 - Deserialization of Untrusted Data in parlai
CVE-2021-24040localpython13 sep 2021
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files c
28RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2020-2865313 sep 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RIESGO
abrir
GitHub PoC1
POC for CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware13 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware13 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque12 sep 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware12 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware12 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque12 sep 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
W1kyri3/Exploit-PoC-CVE-2021-40444-inject-ma-doc-vao-docx
CVE-2021-40444HIGHbajo ataqueransomware12 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC16
Mass exploitation of CVE-2021-24499 unauthenticated upload leading to remote code execution in Workreap theme.
CVE-2021-2449912 sep 2021
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RIESGO
abrir
GitHub PoC1
2021 kernel vulnerability in Ubuntu.
CVE-2021-3493HIGHbajo ataque12 sep 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC
CVE-2021-21972 vCenter-6.5-7.0 RCE POC
CVE-2021-21972CRITICALbajo ataqueransomware12 sep 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC
Reverse engineering the "A Letter Before Court 4.docx" malicious files exploting cve-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware12 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC168
This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit
CVE-2021-40444HIGHbajo ataqueransomware12 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC4
fengjixuchui/CVE-2021-40444-docx-Generate
CVE-2021-40444HIGHbajo ataqueransomware11 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
KnoooW/CVE-2021-40444-docx-Generate
CVE-2021-40444HIGHbajo ataqueransomware11 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC11
A malicious .cab creation tool for CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware11 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1960911 sep 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
GitHub PoC
Strapi Remote Code Execution
CVE-2019-1960911 sep 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
anteriorpágina 655 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.