Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
GitHub PoC21
Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat
CVE-2020-1938CRITICALbajo ataque28 mar 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALbajo ataque28 mar 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC1
Another implementation for linux privilege escalation exploit via snap(d) (CVE-2019-7304)
CVE-2019-7304HIGH28 mar 2021
Local privilege escalation via snapd socket
53RIESGO
abrir
GitHub PoC38
CVE-2021-22192 靶场: 未授权用户 RCE 漏洞
CVE-2021-22192CRITICAL27 mar 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
53RIESGO
abrir
GitHub PoC8
F5 BIG-IP远程代码执行;cve-2021-22986,批量检测;命令执行利用
CVE-2021-22986CRITICALbajo ataqueransomware26 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALbajo ataqueransomware26 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
siramk/CVE-2018-1335
CVE-2018-133526 mar 2021
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-133526 mar 2021
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Exploit-DB
Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
CVE-2012-6708webappshardware25 mar 2021
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RIESGO
abrir
GitHub PoC10
Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
CVE-2021-2789025 mar 2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RIESGO
abrir
GitHub PoC1
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
CVE-2018-999525 mar 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-023225 mar 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
Exploit-DB
Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
CVE-2020-14209webappsphp25 mar 2021
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio
28RIESGO
abrir
GitHub PoC33
Vulnerability analysis and PoC for the Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (RCE)
CVE-2019-023225 mar 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2551CRITICALbajo ataque25 mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
GitHub PoC
Proof of concept for CVE-2020-11819 and CVE-2020-15946
CVE-2020-1181925 mar 2021
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RIESGO
abrir
Metasploit0
macOS Gatekeeper check bypass
CVE-2021-30657MEDIUMbajo ataque25 mar 2021
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2
90RIESGO
abrir
Metasploit0
macOS Gatekeeper check bypass
CVE-2022-2261625 mar 2021
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey
18RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALbajo ataqueransomware24 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC10
CVE-2017-0100、MS17-012、Eop
CVE-2017-010024 mar 2021
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RIESGO
abrir
GitHub PoC52
Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.
CVE-2021-26855CRITICALbajo ataqueransomware24 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2629524 mar 2021
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-27065HIGHbajo ataqueransomware24 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-27065HIGHbajo ataqueransomware23 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
CVE-2021-22986 Checker Script in Python3
CVE-2021-22986CRITICALbajo ataqueransomware23 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
Exploit-DBVexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
CVE-2018-14009webappsmultiple23 mar 2021
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALbajo ataqueransomware23 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
Exploit-DB
MyBB 1.8.25 - Poll Vote Count SQL Injection
CVE-2021-27946webappsphp23 mar 2021
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2629523 mar 2021
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RIESGO
abrir
GitHub PoC
analytics ProxyLogo Mail exchange RCE
CVE-2021-26855CRITICALbajo ataqueransomware23 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 697 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.