Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
GitHub PoC225
CVE-2021-3156 - Sudo Baron Samedit
CVE-2021-3156HIGHbajo ataque29 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
Cacti 1.2.12 - 'filter' SQL Injection
CVE-2020-14295webappsphp29 abr 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir
GitHub PoC1
PoC for CVE-2018-13382, never successfully tested so swim at your own risk
CVE-2018-13382CRITICALbajo ataqueransomware28 abr 2021
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RIESGO
abrir
Exploit-DB
Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS)
CVE-2021-29460HIGHwebappsphp28 abr 2021
Cross-site scripting (XSS) from unsanitized uploaded SVG files
41RIESGO
abrir
GitHub PoC2
Authenticated SQL injection to command execution on Cacti 1.2.12
CVE-2020-1429528 abr 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-2093328 abr 2021
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.
50RIESGO
abrir
Metasploit400
SuiteCRM Log File Remote Code Execution
CVE-2021-4284028 abr 2021
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RIESGO
abrir
Metasploit400
SuiteCRM Log File Remote Code Execution
CVE-2020-2832828 abr 2021
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-13382CRITICALbajo ataqueransomware28 abr 2021
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-895827 abr 2021
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow
35RIESGO
abrir
GitHub PoC10
lsw29475/CVE-2018-8611
CVE-2018-8611HIGHbajo ataque27 abr 2021
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8611HIGHbajo ataque27 abr 2021
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1272527 abr 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC1
streghstreek/CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque27 abr 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC1
CVE-2019-12725 ZeroShell 远程命令执行漏洞
CVE-2019-1272527 abr 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-1389HIGHbajo ataque26 abr 2021
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RIESGO
abrir
Metasploit600
Git LFS Clone Command Exec
CVE-2021-21300HIGH26 abr 2021
malicious repositories can execute remote code while cloning
58RIESGO
abrir
Exploit-DB
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2)
CVE-2021-28419webappsphp26 abr 2021
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads
28RIESGO
abrir
GitHub PoC31
Read my blog for more info -
CVE-2021-1732HIGHbajo ataqueransomware25 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
edsonjt81/sudo-cve-2019-18634
CVE-2019-1863425 abr 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC
edsonjt81/CVE-2019-14287-
CVE-2019-1428725 abr 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHbajo ataqueransomware25 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
rebuild cve
CVE-2021-329125 abr 2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque25 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC2
b1tg/CVE-2018-6065-exploit
CVE-2018-6065HIGHbajo ataque24 abr 2021
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-6065HIGHbajo ataque24 abr 2021
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHbajo ataqueransomware23 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-3318webappsmultiple23 abr 2021
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
23RIESGO
abrir
GitHub PoC66
CVE-2021-1732 poc & exp; tested on 20H2
CVE-2021-1732HIGHbajo ataqueransomware23 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
itssmikefm/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware22 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
anteriorpágina 690 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.