Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC
DXY0411/CVE-2020-23342
CVE-2020-2334202 may 2021
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
28RIESGO
abrir
GitHub PoC1
Completed a working exploit for CVE-2018-17463 for fun.
CVE-2018-17463HIGHbajo ataque02 may 2021
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RIESGO
abrir
GitHub PoC
Abdennour-py/CVE-2021-3493
CVE-2021-3493HIGHbajo ataque02 may 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC
CVE-2003-0264 SLMail5.5_RemoteBufferOverflow
CVE-2003-026401 may 2021
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RIESGO
abrir
GitHub PoC3
vsftpd 2.3.4 Backdoor Exploit
CVE-2011-252301 may 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC2
Confluence unauthorize template injection
CVE-2019-3396CRITICALbajo ataqueransomware01 may 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
Drupal Drupal 8.6.x RCE Exploit
CVE-2019-6340HIGHbajo ataque01 may 2021
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow
CVE-2009-018201 may 2021
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RIESGO
abrir
GitHub PoC7
Apache OFBiz unsafe deserialization of XMLRPC arguments
CVE-2020-949630 abr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
GitHub PoC
lvyoshino/CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware30 abr 2021
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC225
CVE-2021-3156 - Sudo Baron Samedit
CVE-2021-3156HIGHbajo ataque29 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC17
Moodle (< 3.6.2, < 3.5.4, < 3.4.7, < 3.1.16) XSS PoC for Privilege Escalation (Student to Admin)
CVE-2019-3810MEDIUM29 abr 2021
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported vers
38RIESGO
abrir
GitHub PoC2
Authenticated SQL injection to command execution on Cacti 1.2.12
CVE-2020-1429528 abr 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir
GitHub PoC1
PoC for CVE-2018-13382, never successfully tested so swim at your own risk
CVE-2018-13382CRITICALbajo ataqueransomware28 abr 2021
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RIESGO
abrir
GitHub PoC1
streghstreek/CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque27 abr 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC10
lsw29475/CVE-2018-8611
CVE-2018-8611HIGHbajo ataque27 abr 2021
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RIESGO
abrir
GitHub PoC1
CVE-2019-12725 ZeroShell 远程命令执行漏洞
CVE-2019-1272527 abr 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC1
rebuild cve
CVE-2021-329125 abr 2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RIESGO
abrir
GitHub PoC31
Read my blog for more info -
CVE-2021-1732HIGHbajo ataqueransomware25 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
edsonjt81/sudo-cve-2019-18634
CVE-2019-1863425 abr 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC
edsonjt81/CVE-2019-14287-
CVE-2019-1428725 abr 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC2
b1tg/CVE-2018-6065-exploit
CVE-2018-6065HIGHbajo ataque24 abr 2021
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RIESGO
abrir
GitHub PoC66
CVE-2021-1732 poc & exp; tested on 20H2
CVE-2021-1732HIGHbajo ataqueransomware23 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC3
oneoy/CVE-2021-3493
CVE-2021-3493HIGHbajo ataque22 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC
itssmikefm/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware22 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC3
POC exploit for CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware22 abr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC8
Automated tool to exploit sharepoint CVE-2019-0604
CVE-2019-0604CRITICALbajo ataqueransomware22 abr 2021
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
GitHub PoC13
CVE-2021-22192
CVE-2021-22192CRITICAL22 abr 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
53RIESGO
abrir
GitHub PoC
Pulse Connect Secure RCE Vulnerability (CVE-2021-22893)
CVE-2021-22893CRITICALbajo ataqueransomware21 abr 2021
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo
90RIESGO
abrir
GitHub PoC10
DO NOT RUN THIS.
CVE-2021-28480CRITICAL21 abr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
85RIESGO
abrir
anteriorpágina 372 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.