Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
VulnCheck XDB
local
CVE-2013-2094HIGHbajo ataque30 mar 2021
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir
VulnCheck XDB
local
CVE-2014-0196MEDIUMbajo ataque30 mar 2021
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir
VulnCheck XDB
local
CVE-2015-132830 mar 2021
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
VulnCheck XDB
local
CVE-2021-22555HIGHbajo ataque30 mar 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque30 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC11
Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal
CVE-2020-2383930 mar 2021
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa
28RIESGO
abrir
VulnCheck XDB
local
CVE-2014-3153HIGHbajo ataque30 mar 2021
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque30 mar 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware30 mar 2021
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque30 mar 2021
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque30 mar 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC1
A collection of scripts and instructions to test CVE-2014-0160 (heartbleed). ❤️ 🩸
CVE-2014-0160HIGHbajo ataque30 mar 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-13272HIGHbajo ataque30 mar 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-7494CRITICALbajo ataqueransomware30 mar 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque30 mar 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-072830 mar 2021
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC1
CVE-2021-3156漏洞修复Shell
CVE-2021-3156HIGHbajo ataque30 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque30 mar 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
CVE-2019-12840
CVE-2019-1284030 mar 2021
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
Metasploit600
VMware vRealize Operations (vROps) Manager SSRF RCE
CVE-2021-21975HIGHbajo ataqueransomware30 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
Metasploit600
VMware vRealize Operations (vROps) Manager SSRF RCE
CVE-2021-2198330 mar 2021
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authent
50RIESGO
abrir
GitHub PoC4
D-Link DCS系列账号密码信息泄露漏洞,通过脚本获取账号密码,可批量。
CVE-2020-25078HIGHbajo ataque30 mar 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir
GitHub PoC1
CVE-2018-9995 هک دوربین مداربسته با آسیب پذیری
CVE-2018-999530 mar 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Exploit-DB
SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
CVE-2017-15950webappswindows29 mar 2021
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RIESGO
abrir
GitHub PoC247
C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection
CVE-2021-26855CRITICALbajo ataqueransomware29 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC13
Code By:Tas9er / F5 BIG-IP 远程命令执行漏洞
CVE-2021-22986CRITICALbajo ataqueransomware29 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
dotslashed/CVE-2021-22986
CVE-2021-22986CRITICALbajo ataqueransomware29 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
Metasploit300
GravCMS Remote Command Execution
CVE-2021-21425CRITICAL29 mar 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
Exploit-DB
Concrete5 8.5.4 - 'name' Stored XSS
CVE-2021-3111webappsphp29 mar 2021
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.p
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALbajo ataqueransomware29 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 696 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.