Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
78.137 exploits
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque16 jul 2021
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque16 jul 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.19 < 5.9 - 'Netfilter Local Privilege Escalation
CVE-2021-22555HIGHbajo ataquelocallinux15 jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
CVE-2021-25157remotecgi15 jul 2021
A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s
28RIESGO
abrir
Metasploit300
Jetty WEB-INF File Disclosure
CVE-2021-28164MEDIUM15 jul 2021
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RIESGO
abrir
Metasploit300
Jetty WEB-INF File Disclosure
CVE-2021-34429MEDIUM15 jul 2021
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RIESGO
abrir
Metasploit300
Lexmark Driver Privilege Escalation
CVE-2021-3544915 jul 2021
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below,
18RIESGO
abrir
Metasploit600
Nagios XI Autodiscovery Webshell Upload
CVE-2021-3734315 jul 2021
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post au
23RIESGO
abrir
Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
CVE-2021-25162remotecgi15 jul 2021
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
28RIESGO
abrir
Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
CVE-2021-25160remotecgi15 jul 2021
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
23RIESGO
abrir
Exploit-DB
WordPress Plugin Popular Posts 5.3.2 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-42362HIGHwebappsphp15 jul 2021
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RIESGO
abrir
Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
CVE-2021-25155remotecgi15 jul 2021
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RIESGO
abrir
GitHub PoC1
JoneyJunior/cve-2021-22555
CVE-2021-22555HIGHbajo ataque15 jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
CVE-2021-25161remotecgi15 jul 2021
A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve
43RIESGO
abrir
Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
CVE-2021-25156remotecgi15 jul 2021
A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve
35RIESGO
abrir
GitHub PoC1
h3x0v3rl0rd/CVE-2009-2265
CVE-2009-226515 jul 2021
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-1675HIGHbajo ataqueransomware15 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware15 jul 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
CVE-2021-25158remotecgi15 jul 2021
A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s
35RIESGO
abrir
Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
CVE-2021-25159remotecgi15 jul 2021
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3046114 jul 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5689CRITICALbajo ataque14 jul 2021
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir
GitHub PoC
TheWay-hue/CVE-2017-5689-Checker
CVE-2017-5689CRITICALbajo ataque14 jul 2021
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir
GitHub PoC
Wordpress Most Popular Post plugin vuln
CVE-2021-42362HIGH14 jul 2021
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RIESGO
abrir
GitHub PoC1
1stPeak/CVE-2020-0796-Scanner
CVE-2020-0796CRITICALbajo ataqueransomware14 jul 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Exploit-DB
Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)
CVE-2021-31762webappslinux14 jul 2021
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RIESGO
abrir
GitHub PoC
Cve-2021-1675 or cve-2021-34527? Detailed analysis and exploitation of windows print spooler 0day vulnerability!!!
CVE-2021-34527HIGHbajo ataqueransomware13 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
CVE-2019-0221webappsmultiple13 jul 2021
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided
50RIESGO
abrir
Exploit-DB
Apache Tomcat 9.0.0.M1 - Open Redirect
CVE-2018-11784webappsmultiple13 jul 2021
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a r
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-1675HIGHbajo ataqueransomware13 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 672 / 2605siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.