Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
77.151 exploits
GitHub PoC7
POC Checker for ivanti CVE-2024-21887 Command injcetion
CVE-2024-21887CRITICALbajo ataqueransomware14 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir
GitHub PoC
Program ini adalah alat (tool) yang dibuat untuk memeriksa keamanan sistem Minio terkait dengan kerentanan CVE-2022-35919
CVE-2022-35919HIGH13 ene 2024
Authenticated requests for server update admin API allows path traversal in minio
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-6875CRITICAL13 ene 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-5146713 ene 2024
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-065612 ene 2024
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of S
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
GitHub PoC1
Simple Student Attendance System v.1.0 - Multiple SQL injection vulnerabilities - student_form.php and class_form.php
CVE-2023-51801CRITICAL11 ene 2024
SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary
48RIESGO
abrir
Metasploit300
GitLab Password Reset Account Takeover
CVE-2023-7028CRITICALbajo ataque11 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-34470HIGH11 ene 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-5146711 ene 2024
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-6567CRITICAL11 ene 2024
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4907011 ene 2024
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir
Metasploit600
Netis router MW5360 unauthenticated RCE.
CVE-2024-22729CRITICAL11 ene 2024
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter
65RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-28432HIGHbajo ataque11 ene 2024
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
CVE-2024-21887CRITICALbajo ataqueransomware10 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir
Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
CVE-2023-46805HIGHbajo ataqueransomware10 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir
Metasploit300
Wordpress POST SMTP Account Takeover
CVE-2023-6875CRITICAL10 ene 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-48022CRITICAL10 ene 2024
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque09 ene 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware09 ene 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-5146709 ene 2024
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-5016409 ene 2024
Apache Struts: File upload component had a directory traversal vulnerability
45RIESGO
abrir
GitHub PoC1
PoC for CVE-2022-1388 affecting F5 BIG-IP.
CVE-2022-1388CRITICALbajo ataqueransomware09 ene 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-5146708 ene 2024
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4907008 ene 2024
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-3626708 ene 2024
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerabilit
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-3655308 ene 2024
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /w
60RIESGO
abrir
anteriorpágina 433 / 2572siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.