Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
GitHub PoC
Bypass bludit mitigation login form and upload malicious to call a rev shell
CVE-2019-17240LOW22 mar 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
Exploit-DB
WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
CVE-2017-1000170webappsphp22 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RIESGO
abrir
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27890webappsphp22 mar 2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALbajo ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27889webappsphp22 mar 2021
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
23RIESGO
abrir
GitHub PoC18
EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution
CVE-2017-0144HIGHbajo ataqueransomware22 mar 2021
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit600
Apache OFBiz SOAP Java Deserialization
CVE-2021-2629522 mar 2021
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RIESGO
abrir
GitHub PoC91
CVE-2021-22986 & F5 BIG-IP RCE
CVE-2021-22986CRITICALbajo ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
F5 BIG-IP/BIG-IQ iControl Rest API SSRF to RCE
CVE-2021-22986CRITICALbajo ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
kiri-48/CVE-2021-22986
CVE-2021-22986CRITICALbajo ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC4
CVE-2021-22986 F5 BIG-IP iControl 命令执行漏洞
CVE-2021-22986CRITICALbajo ataqueransomware21 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
Microsoft Exchange Proxylogon Exploit Chain EXP分析
CVE-2021-26855CRITICALbajo ataqueransomware21 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-26855CRITICALbajo ataqueransomware21 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALbajo ataqueransomware21 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC1
Exploiting CVE-2016-2555 enumerating and dumping the underlying Database.
CVE-2016-255520 mar 2021
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
GitHub PoC
A vulnerability scanner that detects CVE-2021-22986 vulnerabilities.
CVE-2021-22986CRITICALbajo ataqueransomware20 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC26
cve-2021-22986 f5 rce 漏洞批量检测 poc
CVE-2021-22986CRITICALbajo ataqueransomware19 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-100017019 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RIESGO
abrir
GitHub PoC4
Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)
CVE-2017-100017019 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RIESGO
abrir
GitHub PoC3
Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159) - https://ricardojoserf.github.io/CVE-2021-31159/
CVE-2021-3115919 mar 2021
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag
28RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque19 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque19 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALbajo ataqueransomware19 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware19 mar 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Exploit-DB
LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
CVE-2019-12962webappsphp19 mar 2021
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
38RIESGO
abrir
GitHub PoC4
Exploit generator for sudo CVE-2021-3156
CVE-2021-3156HIGHbajo ataque19 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC27
Whatsapp remote code execution CVE-2019-11932 https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
CVE-2019-1193219 mar 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC
antichown/Scan-Vuln-CVE-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware18 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
PoC Python script as an exercice from tryhackme.
CVE-2012-298218 mar 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALbajo ataqueransomware18 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 698 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.