Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
76.313 exploits
VulnCheck XDB
remote-with-credentials
CVE-2021-29442HIGH25 nov 2024
Authentication bypass
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALbajo ataqueransomware24 nov 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
GitHub PoC
francescobrina/hfs-cve-2014-6287-exploit
CVE-2014-6287CRITICALbajo ataque24 nov 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALbajo ataque24 nov 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC
WolffCorentin/CVE-2019-1663-Binary-Analysis
CVE-2019-1663CRITICAL24 nov 2024
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-10149CRITICALbajo ataque24 nov 2024
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC1
Remote Command Execution into shell from a vulnerable exim service.
CVE-2019-10149CRITICALbajo ataque24 nov 2024
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC1
Xss injection, WonderCMS 3.2.0 -3.4.2
CVE-2023-41425MEDIUM24 nov 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
GitHub PoC
YassDEV221608/CVE-2024-6387
CVE-2024-6387HIGH24 nov 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC
0-Gram/CVE-2022-41040
CVE-2022-41040HIGHbajo ataqueransomware23 nov 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
CVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。
CVE-2023-20198CRITICALbajo ataque23 nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC24
CVE-2024-35250 的 Beacon Object File (BOF) 实现。
CVE-2024-35250HIGHbajo ataque23 nov 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-41040HIGHbajo ataqueransomware23 nov 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-35250HIGHbajo ataque23 nov 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-47246CRITICALbajo ataqueransomware23 nov 2024
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a f
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALbajo ataque23 nov 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware23 nov 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware23 nov 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-20198CRITICALbajo ataque23 nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque23 nov 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
GitHub PoC1
BohemianHacks/CVE-2024-21534-poc
CVE-2024-21534CRITICAL23 nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RIESGO
abrir
GitHub PoC1
CVE-2024-32002 是 Git 中的一个严重漏洞,允许攻击者在用户执行 git clone 操作时远程执行任意代码(RCE)。
CVE-2024-32002CRITICAL23 nov 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection
CVE-2024-52433CRITICAL22 nov 2024
WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864622 nov 2024
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-45519CRITICALbajo ataque22 nov 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2024-7965HIGHbajo ataque22 nov 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RIESGO
abrir
GitHub PoC
punitdarji/Paloalto-CVE-2024-0012
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC2
CVE-2024-0012批量检测脚本
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC
CVE-2024-0012是Palo Alto Networks PAN-OS软件中的一个身份验证绕过漏洞。该漏洞允许未经身份验证的攻击者通过网络访问管理Web界面,获取PAN-OS管理员权限,从而执行管理操作、篡改配置,或利用其他需要身份验证的特权提升漏洞(如CVE-2024-9474)
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-20198CRITICALbajo ataque22 nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
anteriorpágina 328 / 2544siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.