Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
78.258 exploits
GitHub PoC8
Test for CVE-2000-0649, and return an IP address if vulnerable
CVE-2000-064911 feb 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque10 feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution (2)
CVE-2017-5941webappsnodejs10 feb 2021
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RIESGO
abrir
GitHub PoC40
synacktiv/CVE-2021-1782
CVE-2021-1782HIGHbajo ataque10 feb 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1782HIGHbajo ataque10 feb 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque09 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque09 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
Adobe Connect 10 - Username Disclosure
CVE-2023-22232MEDIUMwebappsmultiple09 feb 2021
Adobe Connect Improper Access Control Security feature bypass
70RIESGO
abrir
GitHub PoC
보안취약점 확인
CVE-2021-3156HIGHbajo ataque09 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC205
CVE-2021-3156非交互式执行命令
CVE-2021-3156HIGHbajo ataque09 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC16
sudo heap overflow to LPE, in Go
CVE-2021-3156HIGHbajo ataque09 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Metasploit600
Advantech iView Unauthenticated Remote Code Execution
CVE-2021-2265209 feb 2021
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow a
30RIESGO
abrir
Metasploit600
Micro Focus Operations Bridge Reporter Unauthenticated Command Injection
CVE-2021-22502CRITICALbajo ataque09 feb 2021
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The
100RIESGO
abrir
Metasploit200
Win32k ConsoleControl Offset Confusion
CVE-2022-21882HIGHbajo ataqueransomware09 feb 2021
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
Metasploit200
Win32k ConsoleControl Offset Confusion
CVE-2021-1732HIGHbajo ataqueransomware09 feb 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'Contact name' Stored Cross Site Scripting (XSS)
CVE-2020-18724webappswindows08 feb 2021
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19
23RIESGO
abrir
Metasploit600
NetMotion Mobility Server MvcUtil Java Deserialization
CVE-2021-2691408 feb 2021
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code
40RIESGO
abrir
Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'file name' Stored Cross Site Scripting (XSS)
CVE-2020-18723webappswindows08 feb 2021
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code
23RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque08 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC51
CVE-2021-3156: Sudo heap overflow exploit for Debian 10
CVE-2021-3156HIGHbajo ataque08 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
Fixed version of the Python script to exploit CVE-2018-19571 and CVE-2018-19585 (GitLab 11.4.7 - Authenticated Remote Code Execution) that is available at https://www.exploit-db.com/exploits/49263 (Python 3.9).
CVE-2018-1957108 feb 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RIESGO
abrir
GitHub PoC
Apple Safari Remote Code Execution
CVE-2020-27930HIGHbajo ataque07 feb 2021
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, wat
76RIESGO
abrir
GitHub PoC10
CVE-2020-7384
CVE-2020-7384HIGH07 feb 2021
Client-Side Command Injection in Rapid7 Metasploit
68RIESGO
abrir
GitHub PoC2
Grayhaxor/CVE-2021-21148
CVE-2021-21148HIGHbajo ataque07 feb 2021
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap
76RIESGO
abrir
Metasploit300
NCR Command Center Agent Remote Code Execution
CVE-2021-312207 feb 2021
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (wit
40RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque07 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-27930HIGHbajo ataque07 feb 2021
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, wat
76RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque06 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC7
1N53C/CVE-2021-3156-PoC
CVE-2021-3156HIGHbajo ataque06 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied
CVE-2021-3156HIGHbajo ataque05 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
anteriorpágina 706 / 2609siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.