Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
GitHub PoC
sbladiamond/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque11 sep 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
Strapi Remote Code Execution
CVE-2019-1960911 sep 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-25078HIGHbajo ataque10 sep 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware10 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1743
CVE-2021-40444 PoC
CVE-2021-40444HIGHbajo ataqueransomware10 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
koharin/CVE-2020-0041
CVE-2020-0041HIGHbajo ataque10 sep 2021
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RIESGO
abrir
GitHub PoC1
CVE-2021-40444 Sample
CVE-2021-40444HIGHbajo ataqueransomware10 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC16
rfcxv/CVE-2021-40444-POC
CVE-2021-40444HIGHbajo ataqueransomware09 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Something I wrote for CVE-2019-15107, a Webmin backdoor
CVE-2019-15107CRITICALbajo ataqueransomware09 sep 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC7
CVE-2021-40444 POC
CVE-2021-40444HIGHbajo ataqueransomware09 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
vysecurity/CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware09 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Immersive-Labs-Sec/cve-2021-40444-analysis
CVE-2021-40444HIGHbajo ataqueransomware09 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
maguireja/CVE-2020-25223
CVE-2020-25223CRITICALbajo ataque09 sep 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RIESGO
abrir
GitHub PoC2
根据已知样本反编译代码
CVE-2021-40444HIGHbajo ataqueransomware09 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
CVE-2020-9054 PoC for Zyxel
CVE-2020-9054CRITICALbajo ataque09 sep 2021
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-9054CRITICALbajo ataque09 sep 2021
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware09 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware09 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Confluence OGNL injection
CVE-2021-26084CRITICALbajo ataqueransomware09 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
CVE-2021-26084 patch as provided in "Confluence Security Advisory - 2021-08-25"
CVE-2021-26084CRITICALbajo ataqueransomware08 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-11708CRITICALbajo ataque08 sep 2021
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RIESGO
abrir
GitHub PoC2
Patched Confluence 7.12.2 (CVE-2021-26084)
CVE-2021-26084CRITICALbajo ataqueransomware08 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-26084CRITICALbajo ataqueransomware08 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-5410HIGHbajo ataque08 sep 2021
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
GitHub PoC16
Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware08 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit
CVE-2019-979108 sep 2021
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RIESGO
abrir
Metasploit600
ManageEngine ADSelfService Plus CVE-2021-40539
CVE-2021-40539CRITICALbajo ataqueransomware07 sep 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RIESGO
abrir
GitHub PoC4
alikarimi999/CVE-2021-21315
CVE-2021-21315HIGHbajo ataque07 sep 2021
Command Injection Vulnerability
100RIESGO
abrir
GitHub PoC30
Atlassian Confluence CVE-2021-26084 one-liner mass checker
CVE-2021-26084CRITICALbajo ataqueransomware07 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
Modified Verion of CVE-2016-0792
CVE-2016-079207 sep 2021
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RIESGO
abrir
anteriorpágina 656 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.