Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.290exploits catalogados
36.046CVEs con explotación pública
24.695probados en laboratorio
78.294 exploits
GitHub PoC3
This simple bash script will patch the recently discovered sudo heap overflow vulnerability.
CVE-2021-3156HIGHbajo ataque27 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
CVE-2021-3156
CVE-2021-3156HIGHbajo ataque27 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC18
crisprss/Laravel_CVE-2021-3129_EXP
CVE-2021-3129CRITICALbajo ataqueransomware27 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC1
unauth401/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque27 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC112
CVE-2021-3156
CVE-2021-3156HIGHbajo ataque27 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC79
WebLogic T3/IIOP RCE ExternalizableHelper.class of coherence.jar
CVE-2020-14756CRITICAL27 ene 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware27 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware27 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC69
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware27 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Exploit-DB
Tenda AC5 AC1200 Wireless - 'WiFi Name & Password' Stored Cross Site Scripting
CVE-2021-3186webappshardware26 ene 2021
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RIESGO
abrir
Metasploit600
Sudo Heap-Based Buffer Overflow
CVE-2021-3156HIGHbajo ataque26 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC35
mr-r3b00t/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque26 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)
CVE-2020-14882CRITICALbajo ataquewebappsjava26 ene 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC2
CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441
CVE-2021-344126 ene 2021
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
23RIESGO
abrir
GitHub PoC
Quick and dirty bruteforcer for CVE-2018-7669 (Directory Traversal Vulnerability in Sitecore)
CVE-2018-766925 ene 2021
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application
28RIESGO
abrir
GitHub PoC78
SecPros-Team/laravel-CVE-2021-3129-EXP
CVE-2021-3129CRITICALbajo ataqueransomware25 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC6
SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.
CVE-2017-11882HIGHbajo ataqueransomware25 ene 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC5
用于对WebLogic(10.3.6.0.0 ;12.1.3.0.0 ;12.2.1.3.0; 12.2.1.4.0 ;14.1.1.0.0)进行验证及利用
CVE-2020-14883HIGHbajo ataque25 ene 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware25 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Unauthenticated Command Injection (Metasploit)
CVE-2020-35729webappsphp25 ene 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware25 ene 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-17144HIGHbajo ataque24 ene 2021
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALbajo ataque24 ene 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALbajo ataque24 ene 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-17144HIGHbajo ataque24 ene 2021
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir
GitHub PoC6
CVE-2020-8597 in RM2100
CVE-2020-8597CRITICAL24 ene 2021
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque24 ene 2021
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
killmonday/CVE-2020-17530-s2-061
CVE-2020-17530CRITICALbajo ataque24 ene 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-27950MEDIUMbajo ataque24 ene 2021
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-820924 ene 2021
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe
50RIESGO
abrir
anteriorpágina 710 / 2610siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.