Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
Exploit-DB
WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)
CVE-2021-24308webappsphp28 may 2021
LifterLMS < 4.21.1 - Authenticated Stored XSS in Edit Profile
23RIESGO
abrir
GitHub PoC
Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team)
CVE-2020-7961CRITICALbajo ataque27 may 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3356427 may 2021
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write
60RIESGO
abrir
GitHub PoC1
Multiple vulnerabilities in the vSphere Client (HTML5) were privately reported to VMware. Updates and workarounds are available to address these vulnerabilities in affected VMware products.
CVE-2021-21985CRITICALbajo ataqueransomware27 may 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
GitHub PoC
ykg88/OHTS_IE6052-CVE-2020-17087
CVE-2020-17087HIGHbajo ataque27 may 2021
Windows Kernel Local Elevation of Privilege Vulnerability
71RIESGO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180627 may 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a
40RIESGO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180727 may 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to
23RIESGO
abrir
Exploit-DBVexDay Proof
ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)
CVE-2015-3306remotelinux26 may 2021
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC
POC-CVE-2020-7961-Token-iterate
CVE-2020-7961CRITICALbajo ataque26 may 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
Exploit-DBVexDay Proof
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
CVE-2020-29607webappsphp26 may 2021
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir
Exploit-DB
Codiad 2.8.4 - Remote Code Execution (Authenticated) (3)
CVE-2018-19423webappsmultiple26 may 2021
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
28RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-3355825 may 2021
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, previe
43RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque25 may 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
DarkFlameMaster-bit/CVE-2018-8174_EXP
CVE-2018-8174HIGHbajo ataqueransomware25 may 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
Metasploit600
VMware vCenter Server Virtual SAN Health Check Plugin RCE
CVE-2021-21985CRITICALbajo ataqueransomware25 may 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3356425 may 2021
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21974HIGH25 may 2021
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG
53RIESGO
abrir
GitHub PoC
qianniaoge/CVE-2020-14882_Exploit_Gui
CVE-2020-14882CRITICALbajo ataque25 may 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
Exploit-DB
WordPress Plugin ReDi Restaurant Reservation 21.0307 - 'Comment' Stored Cross-Site Scripting (XSS)
CVE-2021-24299webappsphp24 may 2021
ReDi Restaurant Reservations < 21.0426 - Unauthenticated Stored Cross-Site Scripting (XSS)
23RIESGO
abrir
GitHub PoC
Exploit CVE-2017-9248 Telerik ReMix from Paul Taylor's script. Exploit Telerik lastest version fixed vuln. ReMix by TinoKa & Shaco JX
CVE-2017-9248CRITICALbajo ataque24 may 2021
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
Metasploit600
ExifTool DjVu ANT Perl injection
CVE-2021-22204MEDIUMbajo ataque24 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALbajo ataque24 may 2021
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
GitHub PoC
bgsilvait/WIn-CVE-2021-31166
CVE-2021-31166CRITICALbajo ataque23 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC4
WordPress XXE vulnerability
CVE-2021-29447HIGH23 may 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC
Qualcomm GPU / ARM Mali GPU
CVE-2021-1905HIGHbajo ataque23 may 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon A
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware22 may 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC176
漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、ShowDoc任意文件上传、原创先锋后台未授权、Kyan账号密码泄露、TerraMasterTos任意文件读取、TamronOS-IPTV系统RCE、Wayos防火墙账号密码泄露
CVE-2019-1272522 may 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-3674922 may 2021
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1272522 may 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware22 may 2021
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
anteriorpágina 685 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.