Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque14 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
MariaDB 10.2 - 'wsrep_provider' OS Command Execution
CVE-2021-27928locallinux14 abr 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RIESGO
abrir
Exploit-DB
jQuery 1.2 - Cross-Site Scripting (XSS)
CVE-2020-11022MEDIUMwebappsmultiple14 abr 2021
jQuery has a potential XSS vulnerability
55RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALbajo ataqueransomware13 abr 2021
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALbajo ataque13 abr 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC1
Auto exploit RCE CVE-2020-5902
CVE-2020-5902CRITICALbajo ataqueransomware13 abr 2021
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC1
CVE-2020-17519 Cheetah
CVE-2020-17519CRITICALbajo ataque13 abr 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
Exploit-DB
ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow
CVE-2020-29238webappsmultiple13 abr 2021
An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensi
28RIESGO
abrir
Metasploit300
Cockpit CMS NoSQLi to RCE
CVE-2020-3584613 abr 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
40RIESGO
abrir
Metasploit0
Google Chrome versions before 89.0.4389.128 V8 XOR Typer Out-Of-Bounds Access RCE
CVE-2021-21220HIGHbajo ataque13 abr 2021
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RIESGO
abrir
Metasploit300
Cockpit CMS NoSQLi to RCE
CVE-2020-3584713 abr 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
60RIESGO
abrir
Metasploit500
2021 Ubuntu Overlayfs LPE
CVE-2021-3493HIGHbajo ataque12 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC2
Samba exploit CVE2003-0201
CVE-2003-020112 abr 2021
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RIESGO
abrir
Exploit-DBVexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-2523remoteunix12 abr 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2003-020112 abr 2021
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RIESGO
abrir
GitHub PoC3
GitLab 11.4.7 RCE exploit with different reverse shells. CVE-2018-19571 + CVE-2018-19585
CVE-2018-1957111 abr 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RIESGO
abrir
GitHub PoC
CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞
CVE-2021-3129CRITICALbajo ataqueransomware11 abr 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware10 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
GitHub PoC3
VMWare-CVE-2021-21975 SSRF vulnerability
CVE-2021-21975HIGHbajo ataqueransomware10 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
GitHub PoC5
CVE-2020-35729
CVE-2020-3572909 abr 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RIESGO
abrir
GitHub PoC2
CVE-2021-3317
CVE-2021-331709 abr 2021
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of
35RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque09 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
An exploit to get root in vsftpd 2.3.4 (CVE-2011-2523) written in python
CVE-2011-252309 abr 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC1
CVE-2020–7961 Mass exploit for Script Kiddies
CVE-2020-7961CRITICALbajo ataque09 abr 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21402HIGH09 abr 2021
Unauthenticated Arbitrary File Access in Jellyfin
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALbajo ataque09 abr 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
Exploit-DB
PrestaShop 1.7.6.7 - 'location' Blind Sql Injection
CVE-2020-15160webappsphp09 abr 2021
Blind SQL Injection in PrestaShop
28RIESGO
abrir
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
CVE-2020-12351remotelinux08 abr 2021
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RIESGO
abrir
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
CVE-2020-12352remotelinux08 abr 2021
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RIESGO
abrir
Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
CVE-2021-30147webappsmultiple08 abr 2021
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RIESGO
abrir
anteriorpágina 693 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.