Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
78.056 exploits
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware09 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-9054CRITICALbajo ataque09 sep 2021
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-5410HIGHbajo ataque08 sep 2021
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-11708CRITICALbajo ataque08 sep 2021
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RIESGO
abrir
GitHub PoC2
Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit
CVE-2019-979108 sep 2021
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RIESGO
abrir
GitHub PoC16
Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware08 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
CVE-2021-26084 patch as provided in "Confluence Security Advisory - 2021-08-25"
CVE-2021-26084CRITICALbajo ataqueransomware08 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC2
Patched Confluence 7.12.2 (CVE-2021-26084)
CVE-2021-26084CRITICALbajo ataqueransomware08 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-26084CRITICALbajo ataqueransomware08 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-100000107 sep 2021
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware07 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.
CVE-2021-26084CRITICALbajo ataqueransomware07 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC30
Atlassian Confluence CVE-2021-26084 one-liner mass checker
CVE-2021-26084CRITICALbajo ataqueransomware07 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
Modified Verion of CVE-2016-0792
CVE-2016-079207 sep 2021
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RIESGO
abrir
GitHub PoC4
alikarimi999/CVE-2021-21315
CVE-2021-21315HIGHbajo ataque07 sep 2021
Command Injection Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21315HIGHbajo ataque07 sep 2021
Command Injection Vulnerability
100RIESGO
abrir
Metasploit600
ManageEngine ADSelfService Plus CVE-2021-40539
CVE-2021-40539CRITICALbajo ataqueransomware07 sep 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RIESGO
abrir
Exploit-DB
FlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-39608webappsphp06 sep 2021
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a rem
35RIESGO
abrir
Exploit-DB
OpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR)
CVE-2021-40352webappsphp06 sep 2021
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can re
23RIESGO
abrir
GitHub PoC5
A vulnerability can allow an attacker to guess the automatically generated development mode secret token.
CVE-2019-542006 sep 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
Metasploit300
Netgear PNPX_GetShareFolderList Authentication Bypass
CVE-2021-45511MEDIUM06 sep 2021
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021
33RIESGO
abrir
Metasploit300
WordPress Plugin Automatic Config Change to RCE
CVE-2021-4374CRITICAL06 sep 2021
WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware05 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC
Confluence OGNL Injection [CVE-2021-26084].
CVE-2021-26086MEDIUMbajo ataque05 sep 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RIESGO
abrir
GitHub PoC
BabyTeam1024/cve-2018-2628
CVE-2018-2628CRITICALbajo ataque04 sep 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMbajo ataqueransomware04 sep 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
GitHub PoC1
Wordpress Plainview Activity Monitor Plugin RCE (20161228)
CVE-2018-1587704 sep 2021
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir
GitHub PoC2
CVE-2021-34646 PoC
CVE-2021-34646CRITICAL04 sep 2021
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RIESGO
abrir
GitHub PoC
Setting up POC for CVE-2021-26084
CVE-2021-26084CRITICALbajo ataqueransomware04 sep 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALbajo ataqueransomware04 sep 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
anteriorpágina 660 / 2602siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.