Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.254exploits catalogados
36.016CVEs con explotación pública
24.695probados en laboratorio
78.254 exploits
VulnCheck XDB
local
CVE-2021-21551HIGHbajo ataque02 jun 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
GitHub PoC3
Wordpress XXE injection 구축 자동화 및 PoC
CVE-2021-29447HIGH01 jun 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC2
CVE-2021-21985 Checker.
CVE-2021-21985CRITICALbajo ataqueransomware01 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
GitHub PoC
This script check the CVE-2021-21985 vulnerability and patch on vCenter Server.
CVE-2021-21985CRITICALbajo ataqueransomware01 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21985CRITICALbajo ataqueransomware01 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21985CRITICALbajo ataqueransomware01 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
Exploit-DB
LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)
CVE-2018-16167webappsmultiple01 jun 2021
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
60RIESGO
abrir
GitHub PoC
rnnsz/CVE-2017-15950
CVE-2017-1595031 may 2021
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware31 may 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21389HIGH31 may 2021
BuddyPress privilege escalation via REST API
61RIESGO
abrir
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2017-10271HIGHbajo ataqueransomware31 may 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC226
PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.
CVE-2021-28476CRITICAL31 may 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RIESGO
abrir
GitHub PoC
rnnsz/CVE-2008-4654
CVE-2008-465431 may 2021
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2019-2729CRITICAL31 may 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RIESGO
abrir
GitHub PoC59
arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system
CVE-2021-21551HIGHbajo ataque30 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
GitHub PoC
JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab.
CVE-2017-12149CRITICALbajo ataqueransomware30 may 2021
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALbajo ataqueransomware29 may 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
GitHub PoC213
alt3kx/CVE-2021-21985_PoC
CVE-2021-21985CRITICALbajo ataqueransomware29 may 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
GitHub PoC1
Script to patch your domain computers about the CVE-2021-21551. Privesc on machines that have the driver dbutil_2_3.sys, installed by some DELL tools (BIOS updater, SupportAssist...)
CVE-2021-21551HIGHbajo ataque28 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
Exploit-DB
WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)
CVE-2021-24308webappsphp28 may 2021
LifterLMS < 4.21.1 - Authenticated Stored XSS in Edit Profile
23RIESGO
abrir
GitHub PoC3
My notes for CVE-2004-1561 IceCast exploitation
CVE-2004-156128 may 2021
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
Exploit-DB
Trixbox 2.8.0.4 - 'lang' Path Traversal
CVE-2017-14537webappsphp28 may 2021
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter
50RIESGO
abrir
GitHub PoC1
Cacti v1.2.8 Unauthenticated Remote Code Execution
CVE-2020-881328 may 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-881328 may 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir
Exploit-DBVexDay Proof
PHPFusion 9.03.50 - Remote Code Execution
CVE-2020-24949webappsphp28 may 2021
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RIESGO
abrir
Exploit-DB
Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated)
CVE-2017-14535webappsphp28 may 2021
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php
50RIESGO
abrir
GitHub PoC
Proof of Concept for CVE-2020-14295.
CVE-2020-1429528 may 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180727 may 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to
23RIESGO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180627 may 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a
40RIESGO
abrir
GitHub PoC
Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team)
CVE-2020-7961CRITICALbajo ataque27 may 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
anteriorpágina 684 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.