Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
78.137 exploits
GitHub PoC24
AssassinUKG/Polkit-CVE-2021-3560
CVE-2021-3560HIGHbajo ataque29 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
Metasploit600
ForgeRock / OpenAM Jato Java Deserialization
CVE-2021-35464CRITICALbajo ataqueransomware29 jun 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-1675HIGHbajo ataqueransomware29 jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
ES File Explorer 4.1.9.7.4 - Arbitrary File Read
CVE-2019-6447remoteandroid29 jun 2021
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-34527HIGHbajo ataqueransomware29 jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-22214MEDIUM29 jun 2021
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE
53RIESGO
abrir
VulnCheck XDB
local
CVE-2020-15368MEDIUM29 jun 2021
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering
33RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque29 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-3580MEDIUMbajo ataqueransomware28 jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
100RIESGO
abrir
Exploit-DB
Atlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
CVE-2021-26078webappsmacos28 jun 2021
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before
23RIESGO
abrir
GitHub PoC19
Automated bulk IP or domain scanner for CVE 2020 3580. Cisco ASA and FTD XSS hunter.
CVE-2020-3580MEDIUMbajo ataqueransomware28 jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
100RIESGO
abrir
GitHub PoC13
freeide/CVE-2021-31955-POC
CVE-2021-31955MEDIUMbajo ataque26 jun 2021
Windows Kernel Information Disclosure Vulnerability
85RIESGO
abrir
GitHub PoC
compiled CVE-2015-1328
CVE-2015-132826 jun 2021
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
VulnCheck XDB
local
CVE-2021-2785026 jun 2021
Bypass of the fix for CVE-2019-0195
60RIESGO
abrir
VulnCheck XDB
local
CVE-2021-31955MEDIUMbajo ataque26 jun 2021
Windows Kernel Information Disclosure Vulnerability
85RIESGO
abrir
GitHub PoC9
Hudi233/CVE-2020-3580
CVE-2020-3580MEDIUMbajo ataqueransomware25 jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
100RIESGO
abrir
Exploit-DB
Seeddms 5.1.10 - Remote Command Execution (RCE) (Authenticated)
CVE-2019-12744webappsphp25 jun 2021
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a differe
28RIESGO
abrir
GitHub PoC1
donghyunlee00/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque25 jun 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-3580MEDIUMbajo ataqueransomware25 jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2785025 jun 2021
Bypass of the fix for CVE-2019-0195
60RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque25 jun 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC1
Remote Command Execution through Unvalidated File Upload in SeedDMS versions <5.1.11
CVE-2019-1274424 jun 2021
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a differe
28RIESGO
abrir
Exploit-DB
Adobe ColdFusion 8 - Remote Command Execution (RCE)
CVE-2009-2265webappscfm24 jun 2021
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware24 jun 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
Badbird3/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware24 jun 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC12
GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425)
CVE-2021-21425CRITICAL24 jun 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
Exploit-DB
TP-Link TL-WR841N - Command Injection
CVE-2020-35576webappshardware24 jun 2021
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216
35RIESGO
abrir
Exploit-DB
VMware vCenter Server 7.0 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2021-21972CRITICALbajo ataqueransomwarewebappsmultiple24 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC11
Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.
CVE-2020-1472MEDIUMbajo ataqueransomware23 jun 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
WordPress Plugin WP Google Maps 8.1.11 - Stored Cross-Site Scripting (XSS)
CVE-2021-24383webappsphp23 jun 2021
WP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS)
23RIESGO
abrir
anteriorpágina 677 / 2605siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.