Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
78.056 exploits
VulnCheck XDB
client-side
CVE-2018-999520 ago 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque19 ago 2021
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC11
CVE-2018-19320 LPE Exploit
CVE-2018-19320HIGHbajo ataqueransomware19 ago 2021
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir
VulnCheck XDB
local
CVE-2018-19320HIGHbajo ataqueransomware19 ago 2021
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware18 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow
CVE-2006-1236remotelinux18 ago 2021
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALbajo ataqueransomware18 ago 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMbajo ataqueransomware18 ago 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
GitHub PoC1
CVE-2019-11932
CVE-2019-1193217 ago 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
Exploit-DB
SonicWall NetExtender 10.2.0.300 - Unquoted Service Path
CVE-2020-5147localwindows17 ago 2021
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to
23RIESGO
abrir
GitHub PoC1
Multiple Stored XSS Online Doctor Appointment System
CVE-2021-2579116 ago 2021
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware16 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC30
CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34473CRITICALbajo ataqueransomware16 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
A tool to crash MySQL servers with CVE-2017-3599
CVE-2017-359916 ago 2021
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMbajo ataqueransomware16 ago 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALbajo ataqueransomware16 ago 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque15 ago 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of the victim server. The contents of the stolen data depend on what is there in the memory of the server. It could potentially contain private keys, TLS session keys, usernames, passwords, credit cards, etc. The vulnerability is in the implementation of the Heartbeat protocol, which is used by SSL/TLS to keep the connection alive.
CVE-2014-0160HIGHbajo ataque15 ago 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
tools for automate configure Ubuntu 20.04 enviroment for testing CVE-2021-28476.
CVE-2021-28476CRITICAL15 ago 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RIESGO
abrir
GitHub PoC1
An implementation of CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque14 ago 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC3
WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5
CVE-2021-2414514 ago 2021
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALbajo ataque14 ago 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
GitHub PoC1
Sudo Heap Overflow Baron Samedit
CVE-2021-3156HIGHbajo ataque13 ago 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
GitHub PoC
WpDiscuz 7.0.4 Arbitrary File Upload Exploit
CVE-2020-24186CRITICAL13 ago 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 664 / 2602siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.