Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
77.231 exploits
GitHub PoC5
CVE-2023-41993
CVE-2023-41993HIGHbajo ataque16 oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RIESGO
abrir
GitHub PoC16
testing poc
CVE-2023-41993HIGHbajo ataque16 oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RIESGO
abrir
GitHub PoC
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252316 oct 2023
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-41993HIGHbajo ataque16 oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RIESGO
abrir
Metasploit300
Cisco IOX XE unauthenticated Command Line Interface (CLI) execution
CVE-2023-20198CRITICALbajo ataque16 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
Metasploit300
Cisco IOX XE unauthenticated OS command execution
CVE-2023-20198CRITICALbajo ataque16 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHbajo ataque16 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
Metasploit300
Cisco IOX XE unauthenticated OS command execution
CVE-2023-20273HIGHbajo ataque16 oct 2023
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-41993HIGHbajo ataque16 oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RIESGO
abrir
Metasploit600
Cisco IOX XE Unauthenticated RCE Chain
CVE-2023-20198CRITICALbajo ataque16 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
Metasploit600
Cisco IOX XE Unauthenticated RCE Chain
CVE-2023-20273HIGHbajo ataque16 oct 2023
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RIESGO
abrir
GitHub PoC1
This repository has the sole purpose of rewriting the CVE-2019-9053 script, which in the original publication is written in Python 2.7. I will be using Python 3.
CVE-2019-905316 oct 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC22
A python based exploit to test out rapid reset attack (CVE-2023-44487)
CVE-2023-44487HIGHbajo ataque16 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864615 oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
GitHub PoC202
po6ix/POC-for-CVE-2023-41993
CVE-2023-41993HIGHbajo ataque15 oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-41993HIGHbajo ataque15 oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque15 oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque15 oct 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-4911HIGHbajo ataque14 oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864614 oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
GitHub PoC
PoC for CVE-2023-4911 LooneyTuneables
CVE-2023-4911HIGHbajo ataque14 oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC
Vagebondcur/IMAGE-MAGICK-CVE-2022-44268
CVE-2022-44268MEDIUM13 oct 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHbajo ataque13 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC6
Confluence Data Center & Server 权限提升漏洞 Exploit
CVE-2023-22515CRITICALbajo ataqueransomware13 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC3
Confluence Broken Access Control
CVE-2023-22515CRITICALbajo ataqueransomware13 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC76
Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)
CVE-2023-44487HIGHbajo ataque13 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC1
iveresk-CVE-2023-22515
CVE-2023-22515CRITICALbajo ataqueransomware13 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque13 oct 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque13 oct 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware13 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
anteriorpágina 458 / 2575siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.