Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
78.056 exploits
VulnCheck XDB
initial-access
CVE-2015-835106 ago 2021
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
GitHub PoC1
this script is exploit for wordpress old plugin gwolle
CVE-2015-835106 ago 2021
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
GitHub PoC
CVE-2020-35847, CVE-2020-35848 : Account Takeover
CVE-2020-3584706 ago 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
60RIESGO
abrir
Exploit-DB
CMSuno 1.7 - 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-36654webappsphp05 ago 2021
CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while
23RIESGO
abrir
GitHub PoC4
Pastea/CVE-2017-1000486
CVE-2017-1000486CRITICALbajo ataque05 ago 2021
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALbajo ataque05 ago 2021
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware04 ago 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Metasploit300
Pi-Hole Top Domains API Authenticated Exec
CVE-2021-32706HIGH04 ago 2021
(Authenticated) Remote Code Execution Possible in Web Interface 5.5
48RIESGO
abrir
GitHub PoC
Windows Elevation of Privilege Vulnerability CVE-2021-36934
CVE-2021-36934HIGHbajo ataque04 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC1
An implementation of CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware04 ago 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC4
s4dbrd/CVE-2020-9496
CVE-2020-949604 ago 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
Exploit-DBVexDay Proof
qdPM 9.1 - Remote Code Execution (Authenticated)
CVE-2020-7246webappsphp04 ago 2021
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir
Exploit-DB
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
CVE-2020-9496webappsjava04 ago 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
GitHub PoC1
An implementation of CVE-2016-8740
CVE-2016-874003 ago 2021
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
45RIESGO
abrir
GitHub PoC40
POC of CVE-2021-2394
CVE-2021-2394CRITICAL02 ago 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RIESGO
abrir
GitHub PoC2
POC experiments with Volume Shadow copy Service (VSS)
CVE-2021-36934HIGHbajo ataque02 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC20
POC of CVE-2021-2394
CVE-2021-2394CRITICAL02 ago 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RIESGO
abrir
GitHub PoC
CVE-2018-20250
CVE-2018-20250HIGHbajo ataqueransomware02 ago 2021
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque02 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC3
PenTestical/CVE-2021-22204
CVE-2021-22204MEDIUMbajo ataque02 ago 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC27
AssassinUKG/CVE-2021-22204
CVE-2021-22204MEDIUMbajo ataque02 ago 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC5
My n-day exploit for CVE-2019-18634 (local privilege escalation)
CVE-2019-1863401 ago 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC2
SeriousSAM Auto Exploiter
CVE-2021-36934HIGHbajo ataque01 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque01 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2865331 jul 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RIESGO
abrir
GitHub PoC1
Exploit for CVE-2018-3810
CVE-2018-381030 jul 2021
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir
GitHub PoC10
WordPress Backup Guard Authenticated Remote Code Execution Exploit
CVE-2021-2415530 jul 2021
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC9
Full unauthenticated RCE proof of concept for Rocket.Chat 3.12.1 CVE-2021-22911
CVE-2021-2291130 jul 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque30 jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-381030 jul 2021
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir
anteriorpágina 666 / 2602siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.