Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
VulnCheck XDB
remote-with-credentials
CVE-2019-908117 may 2021
20RIESGO
abrir
GitHub PoC3
Different rules to detect if CVE-2021-31166 is being exploited
CVE-2021-31166CRITICALbajo ataque17 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Subrion CMS 4.2.1 - Arbitrary File Upload
CVE-2018-19422webappsphp17 may 2021
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir
Exploit-DB
IPFire 2.25 - Remote Code Execution (Authenticated)
CVE-2021-33393webappscgi17 may 2021
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It
50RIESGO
abrir
Metasploit600
IPFire 2.25 Core Update 156 and Prior pakfire.cgi Authenticated RCE
CVE-2021-3339317 may 2021
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It
50RIESGO
abrir
GitHub PoC1
0xm4ud/ProFTPD_CVE-2015-3306
CVE-2015-330616 may 2021
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC2
Pega Infinity Password Reset
CVE-2021-27651CRITICAL16 may 2021
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RIESGO
abrir
GitHub PoC60
RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2
CVE-2021-27651CRITICAL16 may 2021
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RIESGO
abrir
GitHub PoC1
PoC of CVE-2019-14322: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-1432216 may 2021
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RIESGO
abrir
GitHub PoC827
Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.
CVE-2021-31166CRITICALbajo ataque16 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALbajo ataque16 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC4
Exploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority on Linux.
CVE-2017-7494CRITICALbajo ataqueransomware15 may 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DBVexDay Proof
Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated)
CVE-2021-31933HIGHwebappsphp14 may 2021
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a paramete
46RIESGO
abrir
GitHub PoC1
This is modified code of 46635 exploit from python2 to python3.
CVE-2019-905314 may 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHbajo ataque13 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-949613 may 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 and WPAD service 'Jscript.dll' - Use-After-Free
CVE-2020-0674HIGHbajo ataquelocalwindows_x86-6413 may 2021
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Exploit-DB
Firefox 72 IonMonkey - JIT Type Confusion
CVE-2019-17026HIGHbajo ataquelocalwindows_x86-6413 may 2021
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RIESGO
abrir
Exploit-DB
ZeroShell 3.9.0 - Remote Command Execution
CVE-2019-12725webappslinux13 may 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC4
weblogic CVE-2021-2109批量验证poc
CVE-2021-2109HIGH13 may 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RIESGO
abrir
GitHub PoC236
Exploit to SYSTEM for CVE-2021-21551
CVE-2021-21551HIGHbajo ataque13 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
GitHub PoC6
CVE-2020-9496和CVE-2021-26295利用dnslog批量验证漏洞poc及exp
CVE-2020-949613 may 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
GitHub PoC12
exiftool arbitrary code execution vulnerability
CVE-2021-22204MEDIUMbajo ataque12 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMbajo ataque12 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMbajo ataque11 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3046111 may 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-881311 may 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir
GitHub PoC3
POC Exploit written in Ruby
CVE-2019-542011 may 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
GitHub PoC96
Python exploit for the CVE-2021-22204 vulnerability in Exiftool
CVE-2021-22204MEDIUMbajo ataque11 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC
fu2x2000/CVE-2017-17058-woo_exploit
CVE-2017-17058HIGH11 may 2021
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RIESGO
abrir
anteriorpágina 687 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.