Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti
23RIESGO
abrir
Referência
CVE-2021-35323
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RIESGO
abrir
Referência
CVE-2021-35464
CVE-2021-35464CRITICALbajo ataqueransomware
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir
Referência
CVE-2021-35464
CVE-2021-35464CRITICALbajo ataqueransomware
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir
Referência
CVE-2021-3560
CVE-2021-3560HIGHbajo ataque
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
Referência
CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Referência
CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Referência
CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Referência
CVE-2021-42697
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RIESGO
abrir
Referência
Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit)
CVE-2021-43339webappsmultiple
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file
23RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
ReferênciaVexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
CVE-2006-2995webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
CVE-2006-2996webappsphp
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
free QBoard 1.1 - 'qb_path' Remote File Inclusion
CVE-2006-2998webappsphp
PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
SaveWeb Portal 3.4 - 'SITE_Path' Remote File Inclusion
CVE-2006-4012webappsphp
Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbit
23RIESGO
abrir
anteriorpágina 497 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.