Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC226
PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.
CVE-2021-28476CRITICAL31 may 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RIESGO
abrir
GitHub PoC
rnnsz/CVE-2008-4654
CVE-2008-465431 may 2021
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir
GitHub PoC59
arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system
CVE-2021-21551HIGHbajo ataque30 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC
JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab.
CVE-2017-12149CRITICALbajo ataqueransomware30 may 2021
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC213
alt3kx/CVE-2021-21985_PoC
CVE-2021-21985CRITICALbajo ataqueransomware29 may 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
GitHub PoC1
Cacti v1.2.8 Unauthenticated Remote Code Execution
CVE-2020-881328 may 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir
GitHub PoC
Proof of Concept for CVE-2020-14295.
CVE-2020-1429528 may 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir
GitHub PoC3
My notes for CVE-2004-1561 IceCast exploitation
CVE-2004-156128 may 2021
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
GitHub PoC1
Script to patch your domain computers about the CVE-2021-21551. Privesc on machines that have the driver dbutil_2_3.sys, installed by some DELL tools (BIOS updater, SupportAssist...)
CVE-2021-21551HIGHbajo ataque28 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC
ykg88/OHTS_IE6052-CVE-2020-17087
CVE-2020-17087HIGHbajo ataque27 may 2021
Windows Kernel Local Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team)
CVE-2020-7961CRITICALbajo ataque27 may 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC1
Multiple vulnerabilities in the vSphere Client (HTML5) were privately reported to VMware. Updates and workarounds are available to address these vulnerabilities in affected VMware products.
CVE-2021-21985CRITICALbajo ataqueransomware27 may 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir
GitHub PoC
POC-CVE-2020-7961-Token-iterate
CVE-2020-7961CRITICALbajo ataque26 may 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC
DarkFlameMaster-bit/CVE-2018-8174_EXP
CVE-2018-8174HIGHbajo ataqueransomware25 may 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC
qianniaoge/CVE-2020-14882_Exploit_Gui
CVE-2020-14882CRITICALbajo ataque25 may 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC
Exploit CVE-2017-9248 Telerik ReMix from Paul Taylor's script. Exploit Telerik lastest version fixed vuln. ReMix by TinoKa & Shaco JX
CVE-2017-9248CRITICALbajo ataque24 may 2021
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
GitHub PoC4
WordPress XXE vulnerability
CVE-2021-29447HIGH23 may 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC
Qualcomm GPU / ARM Mali GPU
CVE-2021-1905HIGHbajo ataque23 may 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon A
71RIESGO
abrir
GitHub PoC
bgsilvait/WIn-CVE-2021-31166
CVE-2021-31166CRITICALbajo ataque23 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC176
漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、ShowDoc任意文件上传、原创先锋后台未授权、Kyan账号密码泄露、TerraMasterTos任意文件读取、TamronOS-IPTV系统RCE、Wayos防火墙账号密码泄露
CVE-2019-1272522 may 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC8
PoC of how to exploit a RCE vulnerability of the example DAGs in Apache Airflow <1.10.11
CVE-2020-11978HIGHbajo ataque22 may 2021
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RIESGO
abrir
GitHub PoC
tuo4n8/CVE-2020-2950
CVE-2020-2950CRITICAL21 may 2021
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RIESGO
abrir
GitHub PoC8
POC for exiftool vuln (CVE-2021-22204).
CVE-2021-22204MEDIUMbajo ataque21 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC24
ch3rn0byl/CVE-2021-21551
CVE-2021-21551HIGHbajo ataque21 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC1
RCE
CVE-2019-7238CRITICALbajo ataque20 may 2021
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir
GitHub PoC
Local Privilege Escalation is a way to take advantage of flaws in code or service administration that can manage regular or guest users for particular device activities or transfer root user privileges to master or client. User rights admin. The licenses or privileges may be violated by such undesired amendments, as the system may be disrupted by frequent users unless they have shell or root authorization. So, someone, someone, it may become dangerous and be used to obtain access to a higher level.
CVE-2019-13272HIGHbajo ataque20 may 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC
CVE-2019-14287
CVE-2019-1428720 may 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
Docker image that lets me study the exploitation of the VIM exploit
CVE-2019-1273520 may 2021
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RIESGO
abrir
GitHub PoC5
simple bash script for exploit CVE-2021-31166
CVE-2021-31166CRITICALbajo ataque19 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
Different rules to detect if CVE-2021-31166 is being exploited
CVE-2021-31166CRITICALbajo ataque17 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 370 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.