Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
8225 exploits
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware06 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21975HIGHbajo ataqueransomware06 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALbajo ataqueransomware06 abr 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque05 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9805HIGHbajo ataque04 abr 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-1745303 abr 2021
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
43RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHbajo ataqueransomware02 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware02 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-949601 abr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware01 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque31 mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-072830 mar 2021
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
VulnCheck XDB
local
CVE-2021-22555HIGHbajo ataque30 mar 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-100000130 mar 2021
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
VulnCheck XDB
local
CVE-2014-3153HIGHbajo ataque30 mar 2021
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-7494CRITICALbajo ataqueransomware30 mar 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
VulnCheck XDB
local
CVE-2015-754730 mar 2021
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
VulnCheck XDB
local
CVE-2014-0196MEDIUMbajo ataque30 mar 2021
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-999530 mar 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-25078HIGHbajo ataque30 mar 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-13272HIGHbajo ataque30 mar 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque30 mar 2021
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque30 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
local
CVE-2017-100036730 mar 2021
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque30 mar 2021
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque30 mar 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque30 mar 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
anteriorpágina 223 / 275siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.