Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
VulnCheck XDB
initial-access
CVE-2017-9805HIGHbajo ataque04 abr 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-1745303 abr 2021
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
43RIESGO
abrir
GitHub PoC
CVE-2019-0708 Exploit
CVE-2019-0708CRITICALbajo ataqueransomware03 abr 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
piruprohacking/CVE-2020-25213
CVE-2020-25213CRITICALbajo ataque03 abr 2021
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
GitHub PoC4
[CVE-2021-21975] VMware vRealize Operations Manager API Server Side Request Forgery (SSRF)
CVE-2021-21975HIGHbajo ataqueransomware02 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
GitHub PoC3
linuxdy/CVE-2021-1732_exp
CVE-2021-1732HIGHbajo ataqueransomware02 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
shreesh1/CVE-2014-0226-poc
CVE-2014-022602 abr 2021
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denia
45RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware02 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
Exploit-DB
F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated)
CVE-2021-22986CRITICALbajo ataqueransomwarewebappshardware02 abr 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHbajo ataqueransomware02 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-949601 abr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware01 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
GitHub PoC1
Vulnmachines/apache-ofbiz-CVE-2020-9496
CVE-2020-949601 abr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
GitHub PoC
Pommaq/CVE-1999-0016-POC
CVE-1999-001601 abr 2021
Land IP denial of service.
45RIESGO
abrir
GitHub PoC27
Nmap script to check vulnerability CVE-2021-21975
CVE-2021-21975HIGHbajo ataqueransomware01 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
GitHub PoC9
hev0x/CVE-2021-26828_ScadaBR_RCE
CVE-2021-26828HIGHbajo ataque31 mar 2021
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RIESGO
abrir
GitHub PoC2
dorkerdevil/CVE-2021-21975
CVE-2021-21975HIGHbajo ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
GitHub PoC13
CVE-2021-21975 vRealize Operations Manager SSRF
CVE-2021-21975HIGHbajo ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
GitHub PoC12
VMWare vRealize SSRF-CVE-2021-21975
CVE-2021-21975HIGHbajo ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
GitHub PoC3
CVE-2020-14882部署冰蝎内存马
CVE-2020-14882CRITICALbajo ataque31 mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque31 mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque30 mar 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque30 mar 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-25078HIGHbajo ataque30 mar 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-100000130 mar 2021
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
VulnCheck XDB
local
CVE-2015-754730 mar 2021
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
VulnCheck XDB
local
CVE-2014-3153HIGHbajo ataque30 mar 2021
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
anteriorpágina 695 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.