Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
78.056 exploits
GitHub PoC53
alt3kx/CVE-2021-26084_PoC
CVE-2021-26084CRITICALbajo ataqueransomware31 ago 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC48
ProxyToken (CVE-2021-33766) : An Authentication Bypass in Microsoft Exchange Server POC exploit
CVE-2021-33766HIGHbajo ataque31 ago 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RIESGO
abrir
GitHub PoC19
Exploit code for CVE-2019-17662
CVE-2019-1766231 ago 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir
GitHub PoC
Strapi <= 3.0.0-beta.17.8 authenticated remote code execution
CVE-2019-1960930 ago 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
Exploit-DB
Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2019-19609webappsmultiple30 ago 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
Exploit-DB
Strapi 3.0.0-beta - Set Password (Unauthenticated)
CVE-2019-18818webappsmultiple30 ago 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1960930 ago 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1960929 ago 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1960929 ago 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1881829 ago 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-25223CRITICALbajo ataque29 ago 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALbajo ataqueransomware29 ago 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC3
guglia001/CVE-2019-18818
CVE-2019-1881829 ago 2021
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
GitHub PoC
BabyTeam1024/CVE-2017-3248
CVE-2017-324829 ago 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir
GitHub PoC7
Strapi Framework Vulnerable to Remote Code Execution
CVE-2019-1960929 ago 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
GitHub PoC9
Exploit for CVE-2019-19609 in Strapi (Remote Code Execution)
CVE-2019-1960929 ago 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
GitHub PoC1
Citrix ADC RCE cve-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware29 ago 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC11
CVE-2020-25223
CVE-2020-25223CRITICALbajo ataque29 ago 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RIESGO
abrir
GitHub PoC1
CVE-2004-2687 DistCC Daemon Command Execution
CVE-2004-268728 ago 2021
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RIESGO
abrir
GitHub PoC
AssassinUKG/CVE-2021-29447
CVE-2021-29447HIGH27 ago 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC1
A proof of concept for CVE-2016-6515
CVE-2016-651526 ago 2021
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RIESGO
abrir
Exploit-DB
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
CVE-2021-3441webappshardware25 ago 2021
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
23RIESGO
abrir
Metasploit600
Atlassian Confluence WebWork OGNL Injection
CVE-2021-26084CRITICALbajo ataqueransomware25 ago 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-6308MEDIUM24 ago 2021
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at
60RIESGO
abrir
GitHub PoC1
Kibana Prototype Pollution
CVE-2019-7609CRITICALbajo ataque24 ago 2021
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC24
my exp for chrome V8 CVE-2021-30551
CVE-2021-30551HIGHbajo ataque22 ago 2021
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru
83RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-30551HIGHbajo ataque22 ago 2021
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru
83RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-35464CRITICALbajo ataqueransomware21 ago 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir
GitHub PoC
rood8008/CVE-2021-35464
CVE-2021-35464CRITICALbajo ataqueransomware21 ago 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir
GitHub PoC1
An implementation of CVE-2015-3306
CVE-2015-330621 ago 2021
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
anteriorpágina 663 / 2602siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.