Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
Exploit-DB
Monica 2.19.1 - 'last_name' Stored XSS
CVE-2021-27370webappsmultiple23 feb 2021
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
23RIESGO
abrir
Metasploit0
VMware vCenter Server Unauthenticated OVA File Upload RCE
CVE-2021-21972CRITICALbajo ataqueransomware23 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque23 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
oneoy/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque23 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC3
Python implementation of 'Username' map script' RCE Exploit for Samba 3.0.20 < 3.0.25rc3 (CVE-2007-2447).
CVE-2007-244722 feb 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC1
Nicoslo/Windows-Exploitation-Web-Server-Tomcat-8.5.39-CVE-2019-0232
CVE-2019-023221 feb 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC1
Nicoslo/Windows-exploitation-Apache-Tomcat-8.5.19-CVE-2019-0232-
CVE-2019-023220 feb 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC
roninAPT/CVE-2018-0802
CVE-2018-0802HIGHbajo ataqueransomware20 feb 2021
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-0802HIGHbajo ataqueransomware20 feb 2021
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
GitHub PoC1
Nicoslo/Windows-exploitation-Rejetto-HTTP-File-Server-HFS-2.3.x-CVE-2014-6287
CVE-2014-6287CRITICALbajo ataque20 feb 2021
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC
Eternit7/CVE-2019-1458
CVE-2019-1458HIGHbajo ataqueransomware19 feb 2021
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC
Full exploit code for CVE-2019-25024 an unauthenticated command injection flaw in OpenRepeater.
CVE-2019-2502419 feb 2021
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy
28RIESGO
abrir
GitHub PoC1
Nicoslo/Windows-exploitation-BadBlue-2.7-CVE-2007-6377
CVE-2007-637718 feb 2021
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware18 feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC163
Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)
CVE-2021-3129CRITICALbajo ataqueransomware18 feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC1
PoC for CVE-2015-1769
CVE-2015-1769MEDIUMbajo ataque17 feb 2021
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,
63RIESGO
abrir
Exploit-DB
TestLink 1.9.20 - Unrestricted File Upload (Authenticated)
CVE-2020-8639webappsphp15 feb 2021
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute ar
28RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-0708CRITICALbajo ataqueransomware15 feb 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALbajo ataqueransomware15 feb 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC3
OpenSSL Heartbleed Bug CVE-2014-0160 Toolkit. Built with ❤ by Christopher Ngo.
CVE-2014-0160HIGHbajo ataque14 feb 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware14 feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC2
FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware14 feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALbajo ataque13 feb 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2564613 feb 2021
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
CVE-2021-25297HIGHbajo ataque13 feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
98RIESGO
abrir
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
CVE-2021-25298HIGHbajo ataque13 feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RIESGO
abrir
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
CVE-2021-25296HIGHbajo ataque13 feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RIESGO
abrir
GitHub PoC4
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker.
CVE-2021-21014CRITICAL13 feb 2021
Magento Commerce Arbitrary Folder Empty Could Lead To Arbitrary Code Execution
48RIESGO
abrir
GitHub PoC11
OpenSMTPD 6.4.0 - 6.6.1 Remote Code Execution PoC exploit
CVE-2020-7247CRITICALbajo ataque13 feb 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM12 feb 2021
Cross site scripting
70RIESGO
abrir
anteriorpágina 705 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.