Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
78.056 exploits
GitHub PoC1
Sudo Heap Overflow Baron Samedit
CVE-2021-3156HIGHbajo ataque13 ago 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque12 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
Exploit-DB
Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)
CVE-2021-37425webappsmultiple12 ago 2021
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workfl
35RIESGO
abrir
GitHub PoC3
Exploit for CVE-2021-36934
CVE-2021-36934HIGHbajo ataque12 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
Jerry-zhuang/CVE-2017-1000117
CVE-2017-100011711 ago 2021
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
Zeek Package to detect cve-2017-2741
CVE-2017-274111 ago 2021
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir
GitHub PoC5
Scanner for CVE-2021-34473, ProxyShell, A Microsoft Exchange On-premise Vulnerability
CVE-2021-34473CRITICALbajo ataqueransomware11 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Xiaomi browser 10.2.4.g - Browser Search History Disclosure
CVE-2018-20523localandroid10 ago 2021
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware10 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC46
nuclei scanner for proxyshell ( CVE-2021-34473 )
CVE-2021-34473CRITICALbajo ataqueransomware10 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHbajo ataqueransomware10 ago 2021
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-31207MEDIUMbajo ataqueransomware10 ago 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALbajo ataqueransomware10 ago 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
ZeroShell命令执行漏洞批量扫描poc+exp
CVE-2019-1272510 ago 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC2
CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware10 ago 2021
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Exploit-DB
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
CVE-2020-35848webappsmultiple10 ago 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
60RIESGO
abrir
GitHub PoC10
Windows Font Driver Type 1 VToHOrigin stack corruption
CVE-2020-1020HIGHbajo ataque10 ago 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RIESGO
abrir
GitHub PoC1
OlivierLaflamme/CVE-2021-36934-export-shadow-volume-POC
CVE-2021-36934HIGHbajo ataque10 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque10 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-1020HIGHbajo ataque10 ago 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1272510 ago 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
Exploit-DB
Amica Prodigy 1.7 - Privilege Escalation
CVE-2021-35312localwindows10 ago 2021
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv
23RIESGO
abrir
Exploit-DB
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
CVE-2020-35847webappsmultiple10 ago 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
60RIESGO
abrir
GitHub PoC
CVE-2021-2109 basic scanner
CVE-2021-2109HIGH09 ago 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RIESGO
abrir
GitHub PoC9
BabyTeam1024/CVE-2021-2394
CVE-2021-2394CRITICAL08 ago 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RIESGO
abrir
VulnCheck XDB
client-side
CVE-2013-3900MEDIUMbajo ataque08 ago 2021
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC
Very basic bash script to exploit the CVE-2019-6447.
CVE-2019-644708 ago 2021
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RIESGO
abrir
GitHub PoC
Modified version of CVE-2019-5736-PoC by Frichetten
CVE-2019-573607 ago 2021
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Metasploit300
Canon Driver Privilege Escalation
CVE-2021-3808507 ago 2021
The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer pro
18RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque07 ago 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
anteriorpágina 665 / 2602siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.