Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
CVE-2021-30147webappsmultiple08 abr 2021
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RIESGO
abrir
GitHub PoC
Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3
CVE-2003-026408 abr 2021
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RIESGO
abrir
Exploit-DB
Composr 10.0.36 - Remote Code Execution
CVE-2021-30149webappsphp08 abr 2021
Composr 10.0.36 allows upload and execution of PHP files.
28RIESGO
abrir
Exploit-DB
Composr CMS 10.0.36 - Cross Site Scripting
CVE-2021-30150webappsphp07 abr 2021
Composr 10.0.36 allows XSS in an XML script.
23RIESGO
abrir
GitHub PoC
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
CVE-2016-209807 abr 2021
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
CVE-2021-1473MEDIUM07 abr 2021
Cisco Small Business RV Series Routers Vulnerabilities
40RIESGO
abrir
Exploit-DB
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
CVE-2020-5377CRITICALwebappswindows07 abr 2021
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RIESGO
abrir
Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
CVE-2021-1472MEDIUM07 abr 2021
Cisco Small Business RV Series Routers Vulnerabilities
50RIESGO
abrir
Exploit-DB
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
CVE-2020-14166webappsmultiple07 abr 2021
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyShell RCE
CVE-2021-34473CRITICALbajo ataqueransomware06 abr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALbajo ataqueransomware06 abr 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALbajo ataqueransomware06 abr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21975HIGHbajo ataqueransomware06 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware06 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyShell RCE
CVE-2021-34523CRITICALbajo ataqueransomware06 abr 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Exploit for CVE-2012-2982
CVE-2012-298206 abr 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyShell RCE
CVE-2021-31207MEDIUMbajo ataqueransomware06 abr 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
GitHub PoC6
[CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE)
CVE-2021-21972CRITICALbajo ataqueransomware06 abr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
Exploit-DB
Google Chrome 81.0.4044 V8 - Remote Code Execution
CVE-2020-6507remotemultiple06 abr 2021
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
28RIESGO
abrir
GitHub PoC
pwn3z/CVE-2019-19781-Citrix
CVE-2019-19781CRITICALbajo ataqueransomware06 abr 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC37
vRealize RCE + Privesc (CVE-2021-21975, CVE-2021-21983, CVE-0DAY-?????)
CVE-2021-21975HIGHbajo ataqueransomware06 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
Exploit-DB
Google Chrome 86.0.4240 V8 - Remote Code Execution
CVE-2020-16040remotemultiple06 abr 2021
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir
GitHub PoC1
Exploit Code for CVE-2020-1472 aka Zerologon
CVE-2020-1472MEDIUMbajo ataqueransomware06 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
capturingcats/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque05 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque05 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC3
Exploiting CVE-2014-7205 by injecting arbitrary JavaScript resulting in Remote Code Execution.
CVE-2014-720505 abr 2021
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RIESGO
abrir
GitHub PoC
delina1/CVE-2018-8174
CVE-2018-8174HIGHbajo ataqueransomware05 abr 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC
delina1/CVE-2018-8174_EXP
CVE-2018-8174HIGHbajo ataqueransomware05 abr 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC1
CVE-2017-9805-Exploit
CVE-2017-9805HIGHbajo ataque04 abr 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC1
CVE-2017-9805-Exploit
CVE-2017-9805HIGHbajo ataque04 abr 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
anteriorpágina 694 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.