Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
77.231 exploits
VulnCheck XDB
local
CVE-2023-36802HIGHbajo ataque23 oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque23 oct 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC8
A PoC for CVE 2023-20198
CVE-2023-20198CRITICALbajo ataque23 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC42
CVE-2013-4786 Go exploitation tool
CVE-2013-478623 oct 2023
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RIESGO
abrir
GitHub PoC33
This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273
CVE-2023-20198CRITICALbajo ataque23 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC41
Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)
CVE-2023-20198CRITICALbajo ataque23 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2013-478623 oct 2023
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALbajo ataque23 oct 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-33044CRITICALbajo ataque22 oct 2023
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC3
haingn/LoHongCam-CVE-2021-33044
CVE-2021-33044CRITICALbajo ataque22 oct 2023
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC1
haingn/HIK-CVE-2021-36260-Exploit
CVE-2021-36260CRITICALbajo ataque22 oct 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware22 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque22 oct 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
banyaksepuh/Mass-CVE-2021-3129-Scanner
CVE-2021-3129CRITICALbajo ataqueransomware22 oct 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware21 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC
ShivamDey/CVE-2021-23017
CVE-2021-2301721 oct 2023
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir
GitHub PoC3
CVE-2023-5360 Auto Shell Upload WordPress Royal Elementor 1.3.78 Shell Upload
CVE-2023-536021 oct 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC
ShivamDey/Samba-CVE-2007-2447-Exploit
CVE-2007-244721 oct 2023
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC
Nielk74/CVE-2023-38831
CVE-2023-38831HIGHbajo ataqueransomware21 oct 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
cve-2023-22515的python利用脚本
CVE-2023-22515CRITICALbajo ataqueransomware21 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC2
WAGO系统远程代码执行漏洞(CVE-2023-1698)
CVE-2023-1698CRITICAL20 oct 2023
WAGO: WBM Command Injection in multiple products
85RIESGO
abrir
GitHub PoC20
Confluence后台rce
CVE-2023-22515CRITICALbajo ataqueransomware20 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC
deIndra/CVE-2023-1698
CVE-2023-1698CRITICAL20 oct 2023
WAGO: WBM Command Injection in multiple products
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864620 oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
GitHub PoC3
yTxZx/CVE-2023-28432
CVE-2023-28432HIGHbajo ataque20 oct 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC4
CISCO CVE POC SCRIPT
CVE-2023-20198CRITICALbajo ataque20 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC6
1vere$k POC on the CVE-2023-20198
CVE-2023-20198CRITICALbajo ataque20 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC
reket99/Cisco_CVE-2023-20198
CVE-2023-20198CRITICALbajo ataque20 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC
yTxZx/CVE-2022-26134
CVE-2022-26134CRITICALbajo ataqueransomware20 oct 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
Joomla Unauthenticated Information Disclosure (CVE-2023-23752) exploit
CVE-2023-23752MEDIUMbajo ataque20 oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
anteriorpágina 456 / 2575siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.