Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.295exploits catalogados
36.048CVEs con explotación pública
24.695probados en laboratorio
78.295 exploits
VulnCheck XDB
initial-access
CVE-2021-21307HIGH15 ene 2021
Remote Code Exploit in Lucee Admin
78RIESGO
abrir
GitHub PoC
Rust implementation of CVE-2018-16763 with some extra features.
CVE-2018-1676315 ene 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC
1nteger-c/CVE-2019-8605
CVE-2019-8605HIGHbajo ataque15 ene 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RIESGO
abrir
Metasploit600
Lucee Administrator imgProcess.cfm Arbitrary File Write
CVE-2021-21307HIGH15 ene 2021
Remote Code Exploit in Lucee Admin
78RIESGO
abrir
VulnCheck XDB
local
CVE-2019-8605HIGHbajo ataque15 ene 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RIESGO
abrir
GitHub PoC18
Exploit script for CVE-2020-7961
CVE-2020-7961CRITICALbajo ataque14 ene 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-6207CRITICALbajo ataque14 ene 2021
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir
GitHub PoC
CVE-2020-17519 EXP
CVE-2020-17519CRITICALbajo ataque14 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALbajo ataque14 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
Exploit-DB
Laravel 8.4.2 debug mode - Remote code execution
CVE-2021-3129CRITICALbajo ataqueransomwarewebappsphp14 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Exploit-DB
Nagios XI 5.7.X - Remote Code Execution RCE (Authenticated)
CVE-2020-35578webappsphp14 ene 2021
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir
GitHub PoC82
PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)
CVE-2020-6207CRITICALbajo ataque14 ene 2021
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALbajo ataque14 ene 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC289
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware13 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Metasploit600
Unauthenticated remote code execution in Ignition
CVE-2021-3129CRITICALbajo ataqueransomware13 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
Starry-lord/CVE-2018-0114
CVE-2018-011413 ene 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware12 ene 2021
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC1
CVE-2017-12615 任意文件写入exp,写入webshell
CVE-2017-12615HIGHbajo ataqueransomware12 ene 2021
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
CVE-2020-16875HIGH12 ene 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
48RIESGO
abrir
Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
CVE-2020-17132CRITICAL12 ene 2021
Microsoft Exchange Remote Code Execution Vulnerability
65RIESGO
abrir
GitHub PoC
AnasTaoutaou/CVE-2019-5420
CVE-2019-542011 ene 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware11 ene 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1751810 ene 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1751810 ene 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALbajo ataque10 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC8
[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read
CVE-2020-17519CRITICALbajo ataque10 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC5
ElmouradiAmine/CVE-2020-7048
CVE-2020-7048CRITICAL09 ene 2021
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any
53RIESGO
abrir
GitHub PoC
CVE-2020-17519
CVE-2020-17519CRITICALbajo ataque08 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
CVE-2020-17519CRITICALbajo ataquewebappsjava08 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALbajo ataque08 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
anteriorpágina 712 / 2610siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.