Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
78.056 exploits
GitHub PoC1
Exploit for CVE-2018-3810
CVE-2018-381030 jul 2021
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque29 jul 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
local
CVE-2019-10149CRITICALbajo ataque29 jul 2021
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC15
Shellshock exploit aka CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque29 jul 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque29 jul 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
CVE-2021-36934 HiveNightmare vulnerability checker and workaround
CVE-2021-36934HIGHbajo ataque29 jul 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
CVE-2018-9276 PRTG < 18.2.39 Reverse Shell (Python3 support)
CVE-2018-9276HIGHbajo ataque29 jul 2021
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-34470HIGH29 jul 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
41RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHbajo ataque29 jul 2021
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
GitHub PoC1
Exploit for CVE-2019-10149
CVE-2019-10149CRITICALbajo ataque29 jul 2021
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
Exploit-DB
CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF)
CVE-2021-29995webappsjava29 jul 2021
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute
23RIESGO
abrir
GitHub PoC1
Local Privilege Escalation via snapd (CVE-2019-7304) Remastered PoC exploit
CVE-2019-7304HIGH28 jul 2021
Local privilege escalation via snapd socket
53RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque28 jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC1
Exploit for CVE-2018-12636
CVE-2018-1263628 jul 2021
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi
35RIESGO
abrir
GitHub PoC2
NYCY_homework_&_meeting
CVE-2021-3560HIGHbajo ataque28 jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC3
To fight against Windows security breach PrintNightmare! (CVE-2021-34527, CVE-2021-1675)
CVE-2021-34527HIGHbajo ataqueransomware28 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
An implementation of CVE-2017-12617
CVE-2017-12617HIGHbajo ataque27 jul 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12617HIGHbajo ataque27 jul 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque27 jul 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC7
HiveNightmare aka SeriousSAM
CVE-2021-36934HIGHbajo ataque27 jul 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC3
haidv35/CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware26 jul 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
Metasploit600
ManageEngine OpManager SumPDU Java Deserialization
CVE-2020-2865326 jul 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RIESGO
abrir
Exploit-DB
Elasticsearch ECE 7.13.3 - Anonymous Database Dump
CVE-2021-22146webappsmultiple26 jul 2021
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
28RIESGO
abrir
Metasploit600
ManageEngine OpManager SumPDU Java Deserialization
CVE-2021-328726 jul 2021
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the
30RIESGO
abrir
GitHub PoC1
0x0D1n/CVE-2021-36934
CVE-2021-36934HIGHbajo ataque26 jul 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque26 jul 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
local
CVE-2021-30807HIGHbajo ataque26 jul 2021
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS
76RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque26 jul 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
Exodusro/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque26 jul 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque25 jul 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
anteriorpágina 667 / 2602siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.