Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
77.302 exploits
GitHub PoC2
CVE-2021-3129 | Laravel Debug Mode Vulnerability
CVE-2021-3129CRITICALbajo ataqueransomware27 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware27 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-346027 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
GitHub PoC1
Exploit for the vulnerability of Ultimate Member Plugin.
CVE-2023-346027 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALbajo ataqueransomware27 jul 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir
GitHub PoC
simple program for joomla scanner CVE-2023-23752 with target list
CVE-2023-23752MEDIUMbajo ataque26 jul 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware26 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMbajo ataque26 jul 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM26 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM26 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
GitHub PoC
Laravel RCE (CVE-2021-3129)
CVE-2021-3129CRITICALbajo ataqueransomware26 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
CVE-2023-32629HIGH26 jul 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RIESGO
abrir
Metasploit600
Greenshot .NET Deserialization Fileformat Exploit
CVE-2023-3463426 jul 2023
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green
38RIESGO
abrir
Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
CVE-2023-2640HIGH26 jul 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-3864625 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMbajo ataque25 jul 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-8644CRITICALbajo ataque25 jul 2023
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RIESGO
abrir
GitHub PoC2
Python script to exploit PlaySMS before 1.4.3
CVE-2020-8644CRITICALbajo ataque25 jul 2023
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RIESGO
abrir
GitHub PoC
Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE
CVE-2021-22204MEDIUMbajo ataque25 jul 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC46
A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.
CVE-2017-7921CRITICALbajo ataque24 jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7921CRITICALbajo ataque24 jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3496024 jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RIESGO
abrir
GitHub PoC1
Learn what is BlueJam CVE-2017-0781
CVE-2017-078124 jul 2023
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
GitHub PoC1
CVE-2022-23305 Log4J JDBCAppender SQl injection POC
CVE-2022-23305CRITICAL24 jul 2023
SQL injection in JDBC Appender in Apache Log4j V1
60RIESGO
abrir
GitHub PoC1
ImageMagick Arbitrary Read Files - CVE-2022-44268
CVE-2022-44268MEDIUM23 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-1177CRITICAL23 jul 2023
Path Traversal: '\..\filename' in mlflow/mlflow
75RIESGO
abrir
Metasploit600
Metabase Setup Token RCE
CVE-2023-3864622 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-4191MEDIUM22 jul 2023
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv
70RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-2287322 jul 2023
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3496022 jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RIESGO
abrir
anteriorpágina 479 / 2577siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.