Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
Metasploit400
Dell DBUtil_2_3.sys IOCTL memmove
CVE-2021-21551HIGHbajo ataque04 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
Metasploit600
Wordpress Plugin Backup Guard - Authenticated Remote Code Execution
CVE-2021-2415504 may 2021
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11581CRITICALbajo ataque04 may 2021
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-856203 may 2021
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC1
事件: 微軟(Microsoft)上周公布了修補遭到駭客攻擊的 Exchange Server 漏洞,全球恐有數萬個組織受到影響。網域與被入侵的Exchange郵件伺服器有關,而這臺伺服器後來被駭客當作C&C中繼站使用,導致接下來發生加密攻擊事故。 嚴重性: 全球企業普遍使用微軟生態系執行日常業務,若遭受駭客攻擊,將造成用戶機敏資料外洩並導致極大損失。雖然微軟已推出更新補釘,但阿戴爾強調這尚未去除儲存在受害伺服器內的後門殼層(webshell),因此就算尚未受到攻擊的企業可以免於被駭風險,駭客仍有時間入侵已被駭的伺服器留下「定時炸彈」。 從2020年開始,美國便不斷指控中國入侵多家醫藥公司及學術單位,試圖竊取疫苗研發機密,這次事件很可能將使中美之間的關係進一步惡化。至於華為、TikTok等中國服務是否會受到這次駭客事件波及,則暫時還不明朗。 漏洞通報程序: 在2年前,曾經拿下資安圈漏洞奧斯卡獎Pwnie Awards「最佳伺服器漏洞獎」戴夫寇爾首席資安研究員Orange Tsai(蔡政達),漏洞通報記錄不勝枚舉,後來因為針對企業常用的SSL VPN進行漏洞研究與通報,更是在全球資安圈聲名大噪。 不過,在今年3月2日卻發生讓Orange Tsai錯愕不已的事情。那就是,他在今年一月跟微軟通報的2個Exchange漏洞,微軟原訂在3月9日對外釋出修補程式,卻突然提前一週,在3月2日便緊急釋出修補程式。原來是因為,在2月26日到2月28日,這個週五下班後到週末這段期間,全球各地發生許多利用微軟Exchange漏洞發動攻擊的資安事件。 攻擊本質: 有人在網路上大量掃描微軟於本月修補的CVE-2020-0688安全漏洞,該漏洞攸關Microsoft Exchange伺服器,呼籲Exchange用戶應儘速修補。 CVE-2020-0688漏洞肇因於Exchange伺服器在安裝時沒能妥善建立唯一金鑰,將允許具備該知識及信箱的授權用戶以系統權限傳遞任意物件,屬於遠端程式攻擊漏洞,該漏洞影響Microsoft Exchange Server 2010 SP3、Microsoft Exchange Server 2013、Microsoft Exchange Server 2016與Microsoft Exchange Server 2019,但只被微軟列為重要(Important)等級的風險。
CVE-2020-0688HIGHbajo ataqueransomware03 may 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Exploit-DB
Piwigo 11.3.0 - 'language' SQL
CVE-2021-27973webappsphp03 may 2021
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
28RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-28482HIGH03 may 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
63RIESGO
abrir
GitHub PoC
Docker-compose to set up a test environment for exploiting CVE-2015-8562
CVE-2015-856203 may 2021
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHbajo ataqueransomware02 may 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-17463HIGHbajo ataque02 may 2021
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RIESGO
abrir
GitHub PoC
Abdennour-py/CVE-2021-3493
CVE-2021-3493HIGHbajo ataque02 may 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC1
Completed a working exploit for CVE-2018-17463 for fun.
CVE-2018-17463HIGHbajo ataque02 may 2021
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RIESGO
abrir
GitHub PoC
DXY0411/CVE-2020-23342
CVE-2020-2334202 may 2021
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
28RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque02 may 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC
Drupal Drupal 8.6.x RCE Exploit
CVE-2019-6340HIGHbajo ataque01 may 2021
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2003-0264 SLMail5.5_RemoteBufferOverflow
CVE-2003-026401 may 2021
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RIESGO
abrir
GitHub PoC
CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow
CVE-2009-018201 may 2021
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-6340HIGHbajo ataque01 may 2021
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC3
vsftpd 2.3.4 Backdoor Exploit
CVE-2011-252301 may 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware01 may 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC2
Confluence unauthorize template injection
CVE-2019-3396CRITICALbajo ataqueransomware01 may 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHbajo ataqueransomware30 abr 2021
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
Exploit-DB
Moodle 3.6.1 - Persistent Cross-Site Scripting (XSS)
CVE-2019-3810MEDIUMwebappsphp30 abr 2021
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported vers
38RIESGO
abrir
Exploit-DB
GNU Wget < 1.18 - Arbitrary File Upload (2)
CVE-2016-4971remotelinux30 abr 2021
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RIESGO
abrir
GitHub PoC7
Apache OFBiz unsafe deserialization of XMLRPC arguments
CVE-2020-949630 abr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
GitHub PoC
lvyoshino/CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware30 abr 2021
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-949630 abr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3012829 abr 2021
Unsafe deserialization in Apache OFBiz
60RIESGO
abrir
Exploit-DB
Cacti 1.2.12 - 'filter' SQL Injection
CVE-2020-14295webappsphp29 abr 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-15982HIGHbajo ataqueransomware29 abr 2021
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
anteriorpágina 689 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.