Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC1
PoC for CVE-2015-1769
CVE-2015-1769MEDIUMbajo ataque17 feb 2021
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,
63RIESGO
abrir
GitHub PoC3
OpenSSL Heartbleed Bug CVE-2014-0160 Toolkit. Built with ❤ by Christopher Ngo.
CVE-2014-0160HIGHbajo ataque14 feb 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC2
FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware14 feb 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC11
OpenSMTPD 6.4.0 - 6.6.1 Remote Code Execution PoC exploit
CVE-2020-7247CRITICALbajo ataque13 feb 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC4
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker.
CVE-2021-21014CRITICAL13 feb 2021
Magento Commerce Arbitrary Folder Empty Could Lead To Arbitrary Code Execution
48RIESGO
abrir
GitHub PoC8
Test for CVE-2000-0649, and return an IP address if vulnerable
CVE-2000-064911 feb 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RIESGO
abrir
GitHub PoC40
synacktiv/CVE-2021-1782
CVE-2021-1782HIGHbajo ataque10 feb 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RIESGO
abrir
GitHub PoC
보안취약점 확인
CVE-2021-3156HIGHbajo ataque09 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC16
sudo heap overflow to LPE, in Go
CVE-2021-3156HIGHbajo ataque09 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC205
CVE-2021-3156非交互式执行命令
CVE-2021-3156HIGHbajo ataque09 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC51
CVE-2021-3156: Sudo heap overflow exploit for Debian 10
CVE-2021-3156HIGHbajo ataque08 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
Fixed version of the Python script to exploit CVE-2018-19571 and CVE-2018-19585 (GitLab 11.4.7 - Authenticated Remote Code Execution) that is available at https://www.exploit-db.com/exploits/49263 (Python 3.9).
CVE-2018-1957108 feb 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RIESGO
abrir
GitHub PoC
Apple Safari Remote Code Execution
CVE-2020-27930HIGHbajo ataque07 feb 2021
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, wat
76RIESGO
abrir
GitHub PoC2
Grayhaxor/CVE-2021-21148
CVE-2021-21148HIGHbajo ataque07 feb 2021
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap
76RIESGO
abrir
GitHub PoC10
CVE-2020-7384
CVE-2020-7384HIGH07 feb 2021
Client-Side Command Injection in Rapid7 Metasploit
68RIESGO
abrir
GitHub PoC7
1N53C/CVE-2021-3156-PoC
CVE-2021-3156HIGHbajo ataque06 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied
CVE-2021-3156HIGHbajo ataque05 feb 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC2
Poc for CVE-2020-14181
CVE-2020-1418105 feb 2021
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RIESGO
abrir
GitHub PoC
46o60/CVE-2019-3396_Confluence
CVE-2019-3396CRITICALbajo ataqueransomware05 feb 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC3
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
CVE-2019-2215HIGHbajo ataque05 feb 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC
DXY0411/CVE-2019-16113
CVE-2019-1611305 feb 2021
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC12
CVE-2021-1994、CVE-2021-2047、CVE-2021-2064、CVE-2021-2108、CVE-2021-2075、CVE-2019-17195、CVE-2020-14756、CVE-2021-2109
CVE-2020-14756CRITICAL04 feb 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RIESGO
abrir
GitHub PoC1
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution for Python3
CVE-2017-12617HIGHbajo ataque04 feb 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC2
simple bash script of F5 BIG-IP TMUI Vulnerability CVE-2020-5902 checker
CVE-2020-5902CRITICALbajo ataqueransomware04 feb 2021
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC
forse01/CVE-2020-25213-Wordpress
CVE-2020-25213CRITICALbajo ataque04 feb 2021
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
GitHub PoC67
CVE-2020-3992 & CVE-2019-5544
CVE-2019-5544CRITICALbajo ataqueransomware04 feb 2021
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RIESGO
abrir
GitHub PoC2
simple bash script of CVE-2020-3452 Cisco ASA / Firepower Read-Only Path Traversal Vulnerability checker
CVE-2020-3452HIGHbajo ataque04 feb 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC67
CVE-2020-3992 & CVE-2019-5544
CVE-2020-3992CRITICALbajo ataqueransomware04 feb 2021
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RIESGO
abrir
GitHub PoC
raymontag/cve-2021-1782
CVE-2021-1782HIGHbajo ataque04 feb 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RIESGO
abrir
GitHub PoC12
CVE-2021-1994、CVE-2021-2047、CVE-2021-2064、CVE-2021-2108、CVE-2021-2075、CVE-2019-17195、CVE-2020-14756、CVE-2021-2109
CVE-2021-1994CRITICAL04 feb 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver
48RIESGO
abrir
anteriorpágina 379 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.