Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
77.231 exploits
GitHub PoC2
CVE-2023-46604环境复现包
CVE-2023-46604CRITICALbajo ataqueransomware16 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC
SynixCyberCrimeMY CVE Exploiter By SamuraiMelayu1337 & ?/h4zzzzzz.scc
CVE-2022-29464CRITICALbajo ataqueransomware16 nov 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC64
CVE-2023-20198 Exploit PoC
CVE-2023-20198CRITICALbajo ataque16 nov 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC
POC repo for CVE-2023-46604
CVE-2023-46604CRITICALbajo ataqueransomware15 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware15 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC
Ansible Playbook for CVE-2023-36845(Juniper Networks Junos OS 远程代码执行漏洞)
CVE-2023-36845CRITICALbajo ataque15 nov 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
Metasploit600
Ray cpu_profile command injection
CVE-2023-6019CRITICAL15 nov 2023
Ray Command Injection in cpu_profile Parameter
85RIESGO
abrir
Metasploit600
Ray Agent Job RCE
CVE-2023-48022CRITICAL15 nov 2023
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RIESGO
abrir
GitHub PoC4
WinRAR-6.22、CVE-2023-38831、CNNVD-202308-1943、DM-202307-003730、QVD-2023-19572漏洞复现
CVE-2023-38831HIGHbajo ataqueransomware15 nov 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
Metasploit300
Ray static arbitrary file read
CVE-2023-6020HIGH15 nov 2023
Ray Static File Local File Include
41RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware15 nov 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44026CRITICALbajo ataque14 nov 2023
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RIESGO
abrir
GitHub PoC
NataliSemi/-CVE-2022-44268
CVE-2022-44268MEDIUM14 nov 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
Metasploit300
WordPress WP Fastest Cache Unauthenticated SQLi (CVE-2023-6063)
CVE-2023-606314 nov 2023
WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection
40RIESGO
abrir
GitHub PoC2
An improved POC exploit based on the reported CVE on exploitdb
CVE-2023-32707HIGH14 nov 2023
‘edit_user’ Capability Privilege Escalation
78RIESGO
abrir
Metasploit600
GitLens Git Local Configuration Exec
CVE-2023-4694414 nov 2023
An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Vis
18RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware13 nov 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Обнаружение эксплойта CVE-2023-28252
CVE-2023-28252HIGHbajo ataqueransomware13 nov 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-41064HIGHbajo ataque13 nov 2023
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
76RIESGO
abrir
GitHub PoC3
MrR0b0t19/CVE-2023-41064
CVE-2023-41064HIGHbajo ataque13 nov 2023
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-5091713 nov 2023
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RIESGO
abrir
GitHub PoC
Log4j Vulnerability RCE - CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware13 nov 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque12 nov 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware12 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque12 nov 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
Spring4Shell Vulnerability RCE - CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque12 nov 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC18
This script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe deserialization within the OpenWire protocol.
CVE-2023-46604CRITICALbajo ataqueransomware12 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC3
huiwen-yayaya/CVE-2023-4863
CVE-2023-4863HIGHbajo ataque11 nov 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC
A simple exploit for CVE-2019-2725.
CVE-2019-2725HIGHbajo ataqueransomware11 nov 2023
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC
ersinerenler/CVE-2023-46022-Code-Projects-Blood-Bank-1.0-OOB-SQL-Injection-Vulnerability
CVE-2023-4602211 nov 2023
SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands
23RIESGO
abrir
anteriorpágina 449 / 2575siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.