Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque18 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC9
CutePHP Cute News 2.1.2 RCE PoC
CVE-2019-1144718 mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
GitHub PoC
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
CVE-2019-20361HIGH18 mar 2021
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RIESGO
abrir
GitHub PoC1
PoC Python script as an exercice from tryhackme.
CVE-2012-298218 mar 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1144718 mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1144717 mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
GitHub PoC
Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated)
CVE-2019-1144717 mar 2021
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-27065HIGHbajo ataqueransomware17 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
rConfig Vendors Auth File Upload RCE
CVE-2022-44384HIGH17 mar 2021
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP fi
36RIESGO
abrir
GitHub PoC4
CVE-2021-26855 proxyLogon metasploit exploit script
CVE-2021-26855CRITICALbajo ataqueransomware17 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALbajo ataqueransomware17 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC51
This is a Poc for BIGIP iControl unauth RCE
CVE-2021-22986CRITICALbajo ataqueransomware17 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC124
ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)
CVE-2021-26855CRITICALbajo ataqueransomware17 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALbajo ataqueransomware17 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALbajo ataqueransomware17 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
VestaCP 0.9.8 - File Upload CSRF
CVE-2021-28379webappsmultiple17 mar 2021
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow
23RIESGO
abrir
GitHub PoC3
Chaining CVE-2021-26855 and CVE-2021-26857 to exploit Microsoft Exchange
CVE-2021-26855CRITICALbajo ataqueransomware16 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque16 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALbajo ataqueransomware16 mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21973MEDIUMbajo ataque16 mar 2021
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR
100RIESGO
abrir
GitHub PoC1
automate me!
CVE-2021-21973MEDIUMbajo ataque16 mar 2021
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR
100RIESGO
abrir
GitHub PoC33
ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth arbitrary-file-write vulnerability, CVE-2021-27065, to get code execution.
CVE-2021-26855CRITICALbajo ataqueransomware16 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-27065HIGHbajo ataqueransomware16 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-27065HIGHbajo ataqueransomware15 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC806
Sudo Baron Samedit Exploit
CVE-2021-3156HIGHbajo ataque15 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
Zenario CMS 8.8.53370 - 'id' Blind SQL Injection
CVE-2021-26830webappsphp15 mar 2021
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin
23RIESGO
abrir
GitHub PoC6
Mr-xn/CVE-2021-26855-d
CVE-2021-26855CRITICALbajo ataqueransomware15 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC28
CVE-2021-26855 & CVE-2021-27065
CVE-2021-26855CRITICALbajo ataqueransomware15 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-26855CRITICALbajo ataqueransomware15 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque15 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
anteriorpágina 699 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.