Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
78.137 exploits
GitHub PoC40
MS17-010_CVE-2017-0143
CVE-2017-0143HIGHbajo ataqueransomware08 jul 2021
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC1
A CVE-2013-2028 implementation
CVE-2013-202808 jul 2021
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-1956HIGHbajo ataque08 jul 2021
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the
100RIESGO
abrir
GitHub PoC2
bartimusprimed/CVE-2021-1675-Yara
CVE-2021-1675HIGHbajo ataqueransomware08 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2020-1956
CVE-2020-1956HIGHbajo ataque08 jul 2021
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the
100RIESGO
abrir
GitHub PoC19
Information on the Windows Spooler vulnerability - CVE-2021-1675; CVE 2021 34527
CVE-2021-1675HIGHbajo ataqueransomware07 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque07 jul 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-1675HIGHbajo ataqueransomware07 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
WordPress Plugin Plainview Activity Monitor 20161228 - Remote Code Execution (RCE) (Authenticated) (2)
CVE-2018-15877webappsphp07 jul 2021
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir
Exploit-DBVexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
CVE-2021-22911webappslinux07 jul 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC42
CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)
CVE-2021-3493HIGHbajo ataque07 jul 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
CVE-2020-7388CRITICAL07 jul 2021
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware07 jul 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
CVE-2020-7387MEDIUM07 jul 2021
Sage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actor
40RIESGO
abrir
GitHub PoC
Simple batch script to disable the Microsoft Print Spooler service from system
CVE-2021-34527HIGHbajo ataqueransomware07 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit500
Netfilter x_tables Heap OOB Write Privilege Escalation
CVE-2021-22555HIGHbajo ataque07 jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
GitHub PoC2
How to fix the PrintNightmare vulnerability
CVE-2021-34527HIGHbajo ataqueransomware07 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC5
Exploits Password Reset Vulnerability in OpenCRX, CVE-2020-7378. Also maintains Stealth by deleting all the password reset mails created by the script
CVE-2020-7378CRITICAL06 jul 2021
CRIXP OpenCRX Unverified Password Change
48RIESGO
abrir
Exploit-DB
Pallets Werkzeug 0.15.4 - Path Traversal
CVE-2019-14322webappspython06 jul 2021
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RIESGO
abrir
GitHub PoC
This simple PowerShell script is in response to the "PrintNightmare" vulnerability. This was designed to give a end user the ability to stop and disable the "Print Spooler" service on their computer while awaiting a fix from Microsoft.
CVE-2021-34527HIGHbajo ataqueransomware05 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1675HIGHbajo ataqueransomware05 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHbajo ataqueransomware05 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
edsonjt81/CVE-2021-1675
CVE-2021-1675HIGHbajo ataqueransomware05 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC77
CVE-2021-1675 (PrintNightmare)
CVE-2021-1675HIGHbajo ataqueransomware05 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC801
A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE
CVE-2021-34527HIGHbajo ataqueransomware05 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
Workaround for Windows Print Spooler Remote Code Execution Vulnerability(CVE-2021-34527). See: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
CVE-2021-34527HIGHbajo ataqueransomware05 jul 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated)
CVE-2021-24155webappsphp05 jul 2021
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC2
OpenEMR < 5.0.1.4 - (Authenticated) File upload - Remote command execution
CVE-2018-1513905 jul 2021
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote
28RIESGO
abrir
GitHub PoC23
Masscanner for Laravel phpunit RCE CVE-2017-9841
CVE-2017-9841CRITICALbajo ataque04 jul 2021
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALbajo ataque04 jul 2021
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
anteriorpágina 674 / 2605siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.