Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
78.137 exploits
GitHub PoC10
freeide2017/CVE-2021-33739-POC
CVE-2021-33739HIGHbajo ataque09 jun 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
Exploit-DB
Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF)
CVE-2021-32403webappshardware09 jun 2021
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mecha
23RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2017-955408 jun 2021
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
Metasploit300
Print Spooler Remote DLL Injection
CVE-2021-1675HIGHbajo ataqueransomware08 jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit300
Print Spooler Remote DLL Injection
CVE-2021-34527HIGHbajo ataqueransomware08 jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2017-9554 Exploit Tool
CVE-2017-955408 jun 2021
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
Exploit-DB
WordPress Plugin wpDiscuz 7.0.4 - Remote Code Execution (Unauthenticated)
CVE-2020-24186CRITICALwebappsphp08 jun 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir
Exploit-DB
Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated)
CVE-2020-24186CRITICALwebappsphp07 jun 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-999507 jun 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC7
suprise4u/CVE-2019-1388
CVE-2019-1388HIGHbajo ataqueransomware07 jun 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
Exploit-DBVexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection (Unauthenticated)
CVE-2021-22911webappslinux07 jun 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC
Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240
CVE-2019-17240LOW07 jun 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC4
kienquoc102/CVE-2018-9995-2
CVE-2018-999507 jun 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Exploit-DB
IcoFX 2.6 - '.ico' Buffer Overflow SEH + DEP Bypass using JOP
CVE-2013-4988localwindows07 jun 2021
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RIESGO
abrir
Exploit-DB
Grav CMS 1.7.10 - Server-Side Template Injection (SSTI) (Authenticated)
CVE-2021-29440HIGHwebappsphp07 jun 2021
Twig allowing dangerous PHP functions by default
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-949606 jun 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
GitHub PoC4
Unsafe Twig processing of static pages leading to RCE in Grav CMS 1.7.10
CVE-2021-29440HIGH06 jun 2021
Twig allowing dangerous PHP functions by default
53RIESGO
abrir
GitHub PoC
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
CVE-2020-949606 jun 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
GitHub PoC181
mr-r3bot/Gitlab-CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware05 jun 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2291105 jun 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC1
Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CVE-2018-7600CRITICALbajo ataqueransomware05 jun 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC71
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedded payload. The exploit was made public as CVE-2010-1240.
CVE-2010-124005 jun 2021
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALbajo ataqueransomware05 jun 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware05 jun 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC29
testanull/Project_CVE-2021-21985_PoC
CVE-2021-21985CRITICALbajo ataqueransomware05 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
GitHub PoC61
Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1
CVE-2021-2291105 jun 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC2
CVE-2021-21985 vmware 6.7-9.8 RCE
CVE-2021-21985CRITICALbajo ataqueransomware04 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
Exploit-DB
Monstra CMS 3.0.4 - Remote Code Execution (Authenticated)
CVE-2018-6383webappsphp04 jun 2021
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALbajo ataqueransomware04 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
Exploit-DB
FUDForum 3.1.0 - 'author' Reflected XSS
CVE-2021-27520webappsphp03 jun 2021
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RIESGO
abrir
anteriorpágina 680 / 2605siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.