Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.287exploits catalogados
36.046CVEs con explotación pública
24.695probados en laboratorio
78.289 exploits
GitHub PoC1021
blasty/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque30 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC1
checking CVE-2021-3156 vulnerability & patch script
CVE-2021-3156HIGHbajo ataque30 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC39
Notes regarding CVE-2021-3156: Heap-Based Buffer Overflow in Sudo
CVE-2021-3156HIGHbajo ataque29 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC1
binw2018/CVE-2021-3156-SCRIPT
CVE-2021-3156HIGHbajo ataque29 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
freeFV/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque29 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
MyBB Hide Thread Content Plugin 1.0 - Information Disclosure
CVE-2021-3337webappsphp29 ene 2021
The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading re
28RIESGO
abrir
Metasploit600
Wordpress Plugin Modern Events Calendar - Authenticated Remote Code Execution
CVE-2021-2414529 ene 2021
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque29 ene 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC116
This python file will decrypt the configurationFile used by hikvision cameras vulnerable to CVE-2017-7921.
CVE-2017-7921CRITICALbajo ataque29 ene 2021
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
Exploit-DB
Quick.CMS 6.7 - Remote Code Execution (Authenticated)
CVE-2020-35754webappsphp29 ene 2021
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl
28RIESGO
abrir
GitHub PoC
pwn3z/CVE-2020-14882-WebLogic
CVE-2020-14882CRITICALbajo ataque29 ene 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
local
CVE-2017-7921CRITICALbajo ataque29 ene 2021
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque29 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
Metasploit Framework 6.0.11 - msfvenom APK template command injection
CVE-2020-7384HIGHlocalmultiple28 ene 2021
Client-Side Command Injection in Rapid7 Metasploit
68RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque28 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
CVE-2020-25538webappsphp28 ene 2021
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and r
23RIESGO
abrir
GitHub PoC5
cve-2021-3156;sudo堆溢出漏洞;漏洞检测
CVE-2021-3156HIGHbajo ataque28 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC3
CVE-2021-3156
CVE-2021-3156HIGHbajo ataque28 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC18
1day research effort
CVE-2021-3156HIGHbajo ataque28 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC4
baka9moe/CVE-2021-3156-Exp
CVE-2021-3156HIGHbajo ataque28 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
CVE-2020-25557webappsphp28 ene 2021
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. A
23RIESGO
abrir
Exploit-DB
Fuel CMS 1.4.1 - Remote Code Execution (2)
CVE-2018-16763webappsphp28 ene 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC2
👻CVE-2017-16995
CVE-2017-1699528 ene 2021
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware27 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware27 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC79
WebLogic T3/IIOP RCE ExternalizableHelper.class of coherence.jar
CVE-2020-14756CRITICAL27 ene 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14756CRITICAL27 ene 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RIESGO
abrir
GitHub PoC
CVE-2021-3156
CVE-2021-3156HIGHbajo ataque27 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC18
crisprss/Laravel_CVE-2021-3129_EXP
CVE-2021-3129CRITICALbajo ataqueransomware27 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
nexcess/sudo_cve-2021-3156
CVE-2021-3156HIGHbajo ataque27 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
anteriorpágina 709 / 2610siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.