Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
GitHub PoC176
漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、ShowDoc任意文件上传、原创先锋后台未授权、Kyan账号密码泄露、TerraMasterTos任意文件读取、TamronOS-IPTV系统RCE、Wayos防火墙账号密码泄露
CVE-2019-1272522 may 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware22 may 2021
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC8
POC for exiftool vuln (CVE-2021-22204).
CVE-2021-22204MEDIUMbajo ataque21 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC
tuo4n8/CVE-2020-2950
CVE-2020-2950CRITICAL21 may 2021
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RIESGO
abrir
GitHub PoC24
ch3rn0byl/CVE-2021-21551
CVE-2021-21551HIGHbajo ataque21 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
Exploit-DB
Microsoft Exchange 2019 - Unauthenticated Email Download (Metasploit)
CVE-2021-26855CRITICALbajo ataqueransomwarewebappswindows21 may 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Solaris SunSSH 11.0 x86 - libpam Remote Root (2)
CVE-2020-14871CRITICALbajo ataqueremotesolaris21 may 2021
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMbajo ataque21 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
Exploit-DB
DELL dbutil_2_3.sys 2.3 - Arbitrary Write to Local Privilege Escalation (LPE)
CVE-2021-21551HIGHbajo ataquelocalwindows21 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHbajo ataque21 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALbajo ataque21 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALbajo ataque20 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALbajo ataque20 may 2021
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir
GitHub PoC
CVE-2019-14287
CVE-2019-1428720 may 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
Docker image that lets me study the exploitation of the VIM exploit
CVE-2019-1273520 may 2021
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RIESGO
abrir
GitHub PoC1
RCE
CVE-2019-7238CRITICALbajo ataque20 may 2021
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir
GitHub PoC
Local Privilege Escalation is a way to take advantage of flaws in code or service administration that can manage regular or guest users for particular device activities or transfer root user privileges to master or client. User rights admin. The licenses or privileges may be violated by such undesired amendments, as the system may be disrupted by frequent users unless they have shell or root authorization. So, someone, someone, it may become dangerous and be used to obtain access to a higher level.
CVE-2019-13272HIGHbajo ataque20 may 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Exploit-DB
WordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS)
CVE-2021-24245webappsphp19 may 2021
Stop Spammers < 2021.9 - Reflected Cross-Site Scripting (XSS)
38RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque19 may 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALbajo ataque19 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC5
simple bash script for exploit CVE-2021-31166
CVE-2021-31166CRITICALbajo ataque19 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Microsoft Exchange 2019 - Unauthenticated Email Download
CVE-2021-26855CRITICALbajo ataqueransomwarewebappswindows18 may 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-300718 may 2021
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead
60RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALbajo ataque18 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-908117 may 2021
20RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALbajo ataque17 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Subrion CMS 4.2.1 - Arbitrary File Upload
CVE-2018-19422webappsphp17 may 2021
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir
GitHub PoC3
Different rules to detect if CVE-2021-31166 is being exploited
CVE-2021-31166CRITICALbajo ataque17 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC12
HTTP Protocol Stack CVE-2021-31166
CVE-2021-31166CRITICALbajo ataque17 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC8
PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause the system to crash.
CVE-2021-31166CRITICALbajo ataque17 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 686 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.