Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.947VulnCheck XDB 8542Nuclei 4243Metasploit 3468✓ solo verificadosrecientespopularesriesgo
13.947 exploits
GitHub PoC★ 1
Create your malicious engine in seconds
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon succ
35RIESGO
abrir ↗GitHub PoC★ 3
CVE-2007-2447 - Samba usermap script
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗GitHub PoC★ 1990
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2021-1675 exploit
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 24
AssassinUKG/Polkit-CVE-2021-3560
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗GitHub PoC★ 19
Automated bulk IP or domain scanner for CVE 2020 3580. Cisco ASA and FTD XSS hunter.
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
100RIESGO
abrir ↗GitHub PoC★ 13
freeide/CVE-2021-31955-POC
Windows Kernel Information Disclosure Vulnerability
85RIESGO
abrir ↗GitHub PoC
compiled CVE-2015-1328
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir ↗GitHub PoC★ 1
donghyunlee00/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC★ 9
Hudi233/CVE-2020-3580
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
100RIESGO
abrir ↗GitHub PoC★ 1
Remote Command Execution through Unvalidated File Upload in SeedDMS versions <5.1.11
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a differe
28RIESGO
abrir ↗GitHub PoC★ 12
GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425)
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir ↗GitHub PoC
Badbird3/CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC★ 11
Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC
m3terpreter/CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗GitHub PoC
pywc/CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir ↗GitHub PoC★ 1
POC-CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir ↗GitHub PoC★ 126
Privilege escalation with polkit - CVE-2021-3560
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗GitHub PoC★ 2
PoC exploit for CVE-2020-7247 OpenSMTPD 6.4.0 < 6.6.1 Remote Code Execution
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir ↗GitHub PoC
h3x0v3rl0rd/CVE-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir ↗GitHub PoC
Polkit - Local Privilege Escalation (CVE-2021-3560)
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗GitHub PoC★ 1
spyx/cve-2019-17240
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir ↗GitHub PoC
polkit exploit script v1.0
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗GitHub PoC
sujaygr8/CVE-2020-3187
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RIESGO
abrir ↗GitHub PoC★ 124
secnigma/CVE-2021-3560-Polkit-Privilege-Esclation
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗GitHub PoC★ 8
CVE-2018-19422 Authenticated Remote Code Execution
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir ↗GitHub PoC★ 2
ZeroShell 3.9.0 Remote Command Injection
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗GitHub PoC★ 1
CVE-2021–22201 Arbitrary file read on Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file
48RIESGO
abrir ↗GitHub PoC★ 19
wpDiscuz 7.0.4 Remote Code Execution
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir ↗GitHub PoC★ 40
a reliable C based exploit and writeup for CVE-2021-3560.
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.