Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC1
Another implementation for linux privilege escalation exploit via snap(d) (CVE-2019-7304)
CVE-2019-7304HIGH28 mar 2021
Local privilege escalation via snapd socket
53RIESGO
abrir
GitHub PoC20
Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat
CVE-2020-1938CRITICALbajo ataque28 mar 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC38
CVE-2021-22192 靶场: 未授权用户 RCE 漏洞
CVE-2021-22192CRITICAL27 mar 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
53RIESGO
abrir
GitHub PoC
siramk/CVE-2018-1335
CVE-2018-133526 mar 2021
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
GitHub PoC8
F5 BIG-IP远程代码执行;cve-2021-22986,批量检测;命令执行利用
CVE-2021-22986CRITICALbajo ataqueransomware26 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC30
Vulnerability analysis and PoC for the Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (RCE)
CVE-2019-023225 mar 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC1
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
CVE-2018-999525 mar 2021
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC
Proof of concept for CVE-2020-11819 and CVE-2020-15946
CVE-2020-1181925 mar 2021
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RIESGO
abrir
GitHub PoC10
Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
CVE-2021-2789025 mar 2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RIESGO
abrir
GitHub PoC52
Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.
CVE-2021-26855CRITICALbajo ataqueransomware24 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC10
CVE-2017-0100、MS17-012、Eop
CVE-2017-010024 mar 2021
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RIESGO
abrir
GitHub PoC3
CVE-2021-22986 Checker Script in Python3
CVE-2021-22986CRITICALbajo ataqueransomware23 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
analytics ProxyLogo Mail exchange RCE
CVE-2021-26855CRITICALbajo ataqueransomware23 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC18
EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution
CVE-2017-0144HIGHbajo ataqueransomware22 mar 2021
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC91
CVE-2021-22986 & F5 BIG-IP RCE
CVE-2021-22986CRITICALbajo ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
kiri-48/CVE-2021-22986
CVE-2021-22986CRITICALbajo ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
F5 BIG-IP/BIG-IQ iControl Rest API SSRF to RCE
CVE-2021-22986CRITICALbajo ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
Bypass bludit mitigation login form and upload malicious to call a rev shell
CVE-2019-17240LOW22 mar 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC
Microsoft Exchange Proxylogon Exploit Chain EXP分析
CVE-2021-26855CRITICALbajo ataqueransomware21 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC4
CVE-2021-22986 F5 BIG-IP iControl 命令执行漏洞
CVE-2021-22986CRITICALbajo ataqueransomware21 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
A vulnerability scanner that detects CVE-2021-22986 vulnerabilities.
CVE-2021-22986CRITICALbajo ataqueransomware20 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC1
Exploiting CVE-2016-2555 enumerating and dumping the underlying Database.
CVE-2016-255520 mar 2021
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
GitHub PoC4
Exploit generator for sudo CVE-2021-3156
CVE-2021-3156HIGHbajo ataque19 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC3
Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159) - https://ricardojoserf.github.io/CVE-2021-31159/
CVE-2021-3115919 mar 2021
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag
28RIESGO
abrir
GitHub PoC27
Whatsapp remote code execution CVE-2019-11932 https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
CVE-2019-1193219 mar 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC27
cve-2021-22986 f5 rce 漏洞批量检测 poc
CVE-2021-22986CRITICALbajo ataqueransomware19 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC4
Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)
CVE-2017-100017019 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RIESGO
abrir
GitHub PoC1
PoC Python script as an exercice from tryhackme.
CVE-2012-298218 mar 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
GitHub PoC
antichown/Scan-Vuln-CVE-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware18 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
CVE-2019-20361HIGH18 mar 2021
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RIESGO
abrir
anteriorpágina 375 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.