Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
GitHub PoC★ 96
synacktiv/CVE-2024-43468
CVE-2024-43468CRITICALbajo ataque26 nov 2024
Microsoft Configuration Manager Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2024-38193HIGHbajo ataque26 nov 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
76RIESGO
abrir ↗
GitHub PoC★ 3
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation
CVE-2024-10542CRITICAL26 nov 2024
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-38646—26 nov 2024
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗
GitHub PoC★ 1
Proof Of Concept for the CVE-2012-1831 (Kingview Touchview 6.53). This is a Industrial Control Systems Vulnerability
CVE-2012-1831—26 nov 2024
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted p
28RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-45354MEDIUM26 nov 2024
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-43468CRITICALbajo ataque26 nov 2024
Microsoft Configuration Manager Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2017-0143HIGHbajo ataqueransomware26 nov 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALbajo ataque26 nov 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-12635—26 nov 2024
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir ↗
GitHub PoC★ 3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2021-36260CRITICALbajo ataque26 nov 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-22911—26 nov 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque26 nov 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6278HIGHbajo ataque26 nov 2024
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir ↗
GitHub PoC★ 1
Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible
CVE-2014-6271CRITICALbajo ataque26 nov 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-32784HIGH26 nov 2024
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-41277CRITICALbajo ataque26 nov 2024
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-51567CRITICALbajo ataqueransomware26 nov 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir ↗
GitHub PoC★ 3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2017-7921CRITICALbajo ataque26 nov 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗
GitHub PoC
Picsmize <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-52380CRITICAL25 nov 2024
WordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque25 nov 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗
GitHub PoC
Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you cannot upgrade Magento or cannot apply the official patches, try this one.
CVE-2022-24086CRITICALbajo ataque25 nov 2024
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2021-29442HIGH25 nov 2024
Authentication bypass
68RIESGO
abrir ↗
GitHub PoC
Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection
CVE-2024-52430CRITICAL25 nov 2024
WordPress Lis Video Gallery plugin <= 0.2.1 - PHP Object Injection vulnerability
48RIESGO
abrir ↗
GitHub PoC
Working Dirty Pipe (CVE-2022-0847) exploit tool with root access and file overwrites.
CVE-2022-0847HIGHbajo ataque25 nov 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALbajo ataqueransomware24 nov 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir ↗
GitHub PoC
WolffCorentin/CVE-2019-1663-Binary-Analysis
CVE-2019-1663CRITICAL24 nov 2024
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir ↗
GitHub PoC★ 1
Xss injection, WonderCMS 3.2.0 -3.4.2
CVE-2023-41425MEDIUM24 nov 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗
GitHub PoC★ 1
Remote Command Execution into shell from a vulnerable exim service.
CVE-2019-10149CRITICALbajo ataque24 nov 2024
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗
GitHub PoC
francescobrina/hfs-cve-2014-6287-exploit
CVE-2014-6287CRITICALbajo ataque24 nov 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗
← anteriorpágina 400 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.