Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.245exploits catalogados
34.801CVEs con explotación pública
24.695probados en laboratorio
76.247 exploits
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL27 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC1
letsr00t/CVE-2023-2163
CVE-2023-2163CRITICAL27 nov 2024
Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation
48RIESGO
abrir
GitHub PoC7
A PoC exploit for CVE-2024-10914 - D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL27 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
local
CVE-2015-132827 nov 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
GitHub PoC
dlink vulnerability thing in python and rust
CVE-2024-10914CRITICAL27 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
local
CVE-2024-38193HIGHbajo ataque26 nov 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC96
synacktiv/CVE-2024-43468
CVE-2024-43468CRITICALbajo ataque26 nov 2024
Microsoft Configuration Manager Remote Code Execution Vulnerability
90RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-43468CRITICALbajo ataque26 nov 2024
Microsoft Configuration Manager Remote Code Execution Vulnerability
90RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2291126 nov 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-45354MEDIUM26 nov 2024
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RIESGO
abrir
GitHub PoC1
Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible
CVE-2014-6271CRITICALbajo ataque26 nov 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2021-36260CRITICALbajo ataque26 nov 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-51567CRITICALbajo ataqueransomware26 nov 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-32784HIGH26 nov 2024
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6278HIGHbajo ataque26 nov 2024
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque26 nov 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALbajo ataque26 nov 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque26 nov 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1263526 nov 2024
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC1
Proof Of Concept for the CVE-2012-1831 (Kingview Touchview 6.53). This is a Industrial Control Systems Vulnerability
CVE-2012-183126 nov 2024
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted p
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864626 nov 2024
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2017-7921CRITICALbajo ataque26 nov 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC3
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation
CVE-2024-10542CRITICAL26 nov 2024
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
53RIESGO
abrir
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2022-28171HIGH26 nov 2024
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
53RIESGO
abrir
GitHub PoC
Picsmize <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-52380CRITICAL25 nov 2024
WordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection
CVE-2024-52430CRITICAL25 nov 2024
WordPress Lis Video Gallery plugin <= 0.2.1 - PHP Object Injection vulnerability
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-29442HIGH25 nov 2024
Authentication bypass
68RIESGO
abrir
GitHub PoC
Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you cannot upgrade Magento or cannot apply the official patches, try this one.
CVE-2022-24086CRITICALbajo ataque25 nov 2024
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir
GitHub PoC
Working Dirty Pipe (CVE-2022-0847) exploit tool with root access and file overwrites.
CVE-2022-0847HIGHbajo ataque25 nov 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque25 nov 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
anteriorpágina 325 / 2542siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.