Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
8216 exploits
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMbajo ataqueransomware16 ago 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware16 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALbajo ataqueransomware16 ago 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque15 ago 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALbajo ataque14 ago 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque13 ago 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALbajo ataqueransomware13 ago 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque12 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque10 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHbajo ataqueransomware10 ago 2021
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1272510 ago 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-31207MEDIUMbajo ataqueransomware10 ago 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALbajo ataqueransomware10 ago 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-1020HIGHbajo ataque10 ago 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware10 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2013-3900MEDIUMbajo ataque08 ago 2021
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque07 ago 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-835106 ago 2021
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALbajo ataque05 ago 2021
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware04 ago 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque02 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
local
CVE-2021-36934HIGHbajo ataque01 ago 2021
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2865331 jul 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-381030 jul 2021
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque30 jul 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
anteriorpágina 215 / 274siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.