Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
76.313 exploits
VulnCheck XDB
client-side
CVE-2020-27950MEDIUMbajo ataque15 sep 2024
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-6782CRITICAL15 sep 2024
Calibre Remote Code Execution
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-27564MEDIUM15 sep 2024
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-1071CRITICAL15 sep 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
GitHub PoC
New exploit for pyLoad v0.5.0 - Unauthenticated remote code excecution
CVE-2023-0297CRITICAL15 sep 2024
Code Injection in pyload/pyload
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALbajo ataque14 sep 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC19
Exploit for CVE-2024-29847
CVE-2024-29847CRITICAL14 sep 2024
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-8503CRITICAL14 sep 2024
VICIdial Unauthenticated SQL Injection
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL14 sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC2
chsxthwik/CVE-2024-2876
CVE-2024-2876CRITICAL14 sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC
0xWhoami35/CVE-2024-4879
CVE-2024-4879CRITICALbajo ataque13 sep 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
GitHub PoC3
Proof-of-Concept Exploit for CVE-2024-36401 GeoServer 2.25.1
CVE-2024-36401CRITICALbajo ataque13 sep 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALbajo ataque13 sep 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3383113 sep 2024
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque13 sep 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC2
Robocopsita/CVE-2022-0944_RCE_POC
CVE-2022-0944CRITICAL13 sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir
GitHub PoC
acidburn2049/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque13 sep 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
sshipanoo/CVE-2024-44542
CVE-2024-44542CRITICAL13 sep 2024
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.
48RIESGO
abrir
GitHub PoC
🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker successfully bypassed authentication, gaining admin control over the device! Immediate containment was critical. Stay vigilant! 💻🔐
CVE-2023-20198CRITICALbajo ataque13 sep 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC
Event ID 189 Rule Name SOC227 Microsoft SharePoint Server Elevation of Privilege Possible CVE-2023-29357 .. Exploitation
CVE-2023-29357CRITICALbajo ataqueransomware12 sep 2024
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)
CVE-2024-1709CRITICALbajo ataqueransomware12 sep 2024
Authentication bypass using an alternate path or channel
100RIESGO
abrir
GitHub PoC
pwning netconsd
CVE-2023-28753CRITICAL12 sep 2024
netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware12 sep 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
Old weaponized CVE-2022-1388 exploit.
CVE-2022-1388CRITICALbajo ataqueransomware12 sep 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC2
phirojshah/CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware12 sep 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
🚨 New Incident Report Completed! 🚨 Just wrapped up "Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)" on LetsDefend.io. This analysis involved investigating an attempted Command Injection targeting our PHP server. Staying ahead of these threats with continuous monitoring and swift containment! 🛡️
CVE-2024-4577CRITICALbajo ataqueransomware12 sep 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
CVE-2024-8277 - 0Day Auto Exploit Authentication Bypass in WooCommerce Photo Reviews Plugin
CVE-2024-8277CRITICAL12 sep 2024
WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware12 sep 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC
My proof of concept for CVE-2019 Microsoft-Edge
CVE-2019-056711 sep 2024
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
Metasploit300
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
CVE-2024-8529CRITICAL11 sep 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RIESGO
abrir
anteriorpágina 347 / 2544siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.