Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
77.231 exploits
Metasploit600
PyTorch Model Server Registration and Deserialization RCE
CVE-2022-1471HIGH03 oct 2023
Remote Code execution in SnakeYAML
58RIESGO
abrir
Metasploit600
Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
CVE-2023-4911HIGHbajo ataque03 oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-044103 oct 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
VulnCheck XDB
local
CVE-2023-21768HIGH02 oct 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-38743HIGH02 oct 2023
Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
46RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALbajo ataque02 oct 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC1
Analysis of WS_FTP CVE
CVE-2023-40044CRITICALbajo ataqueransomware02 oct 2023
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RIESGO
abrir
GitHub PoC4
CVE-2023-36845 PoC script automates the PoC for CVE-2023-36845 targeting Juniper Networks Junos OS's J-Web component on EX and SRX Series devices. It exploits a PHP flaw, allowing remote modification of the PHPRC variable. Successful exploitation can lead to code injection and execution.
CVE-2023-36845CRITICALbajo ataque02 oct 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC39
A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654
CVE-2023-43654CRITICAL02 oct 2023
TorchServe Server-Side Request Forgery
75RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-43654CRITICAL02 oct 2023
TorchServe Server-Side Request Forgery
75RIESGO
abrir
VulnCheck XDB
local
CVE-2023-44976LOW01 oct 2023
Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified
28RIESGO
abrir
GitHub PoC1
simrotion13/CVE-2023-36845
CVE-2023-36845CRITICALbajo ataque01 oct 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-36845CRITICALbajo ataque01 oct 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-29357CRITICALbajo ataqueransomware30 sep 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC6
navreet1425/CVE-2021-34621
CVE-2021-34621CRITICAL30 sep 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir
GitHub PoC54
LuemmelSec/CVE-2023-29357
CVE-2023-29357CRITICALbajo ataqueransomware30 sep 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC6
Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129
CVE-2023-4863HIGHbajo ataque30 sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34621CRITICAL30 sep 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir
GitHub PoC
jytmX/CVE-2021-24499
CVE-2021-2449929 sep 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RIESGO
abrir
GitHub PoC
go CVE-2023-24538 patch issue resolver - Kirkstone
CVE-2023-24538CRITICAL29 sep 2023
Backticks not treated as string delimiters in html/template
48RIESGO
abrir
GitHub PoC
go CVE-2023-24538 patch issue resolver - Dunfell
CVE-2023-24538CRITICAL29 sep 2023
Backticks not treated as string delimiters in html/template
48RIESGO
abrir
GitHub PoC3
CVE-2023-36845 - Juniper Firewall Remote code execution (RCE)
CVE-2023-36845CRITICALbajo ataque29 sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC5
Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129
CVE-2023-4863HIGHbajo ataque29 sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-36845CRITICALbajo ataque29 sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC46
JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit
CVE-2023-42793CRITICALbajo ataqueransomware29 sep 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2449929 sep 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware29 sep 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-36884HIGHbajo ataqueransomware28 sep 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC3
PoC for Stored XSS (CVE-2023-43770) Vulnerability
CVE-2023-43770MEDIUMbajo ataque28 sep 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RIESGO
abrir
GitHub PoC41
MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit
CVE-2023-36884HIGHbajo ataqueransomware28 sep 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir
anteriorpágina 462 / 2575siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.