Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.322exploits catalogados
38.524CVEs con explotación pública
24.695probados en laboratorio
82.322 exploits
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC★ 3
Miro Desktop 0.8.18 on macOS allows Electron code injection.
CVE-2024-23746CRITICAL26 ene 2024
Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in
48RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque26 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC★ 209
CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC★ 81
CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner.
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC★ 2
vmtyan/poc-cve-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC★ 101
binganao/CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque26 ene 2024
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗
GitHub PoC
Python Code for Exploit Automation CVE-2023-7028
CVE-2023-7028CRITICALbajo ataque26 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC★ 3
Repository to install CVE-2023-7028 vulnerable Gitlab instance
CVE-2023-7028CRITICALbajo ataque25 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC★ 5
CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server PoC
CVE-2023-22527CRITICALbajo ataqueransomware25 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
GitHub PoC
CVE-2024-23739
CVE-2024-23740CRITICAL25 ene 2024
An issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode
48RIESGO
abrir ↗
GitHub PoC★ 1
Atlassian Confluence Remote Code Execution(RCE) Proof Of Concept
CVE-2023-22527CRITICALbajo ataqueransomware25 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
GitHub PoC
CVE-2024-23741
CVE-2024-23741CRITICAL25 ene 2024
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware25 ene 2024
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 3
CVE-2024-23739
CVE-2024-23739CRITICAL25 ene 2024
An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunA
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware25 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
GitHub PoC★ 3
Proof of concept for the vulnerability CVE-2018-19410
CVE-2018-19410CRITICALbajo ataque25 ene 2024
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privile
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46805HIGHbajo ataqueransomware25 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware25 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-19410CRITICALbajo ataque25 ene 2024
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privile
100RIESGO
abrir ↗
GitHub PoC
Esto es una prueba de concepto propia i basica de la vulneravilidad CVE-2019-12840 la qual te da un RCE en root
CVE-2019-12840—25 ene 2024
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir ↗
GitHub PoC★ 2
whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POC
CVE-2020-1472MEDIUMbajo ataqueransomware25 ene 2024
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir ↗
Metasploit300
GitLab Tags RSS feed email disclosure
CVE-2023-5612MEDIUM25 ene 2024
Missing Authorization in GitLab
28RIESGO
abrir ↗
GitHub PoC★ 2
CVE-2023-46805 Ivanti POC RCE - Ultra fast scanner.
CVE-2023-46805HIGHbajo ataqueransomware25 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
GitHub PoC★ 58
mistymntncop/CVE-2022-4262
CVE-2022-4262HIGHbajo ataque24 ene 2024
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corru
76RIESGO
abrir ↗
Metasploit300
Zyxel parse_config.py Command Injection
CVE-2023-33012HIGH24 ene 2024
A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.3
36RIESGO
abrir ↗
← anteriorpágina 502 / 2745siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.