Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.322exploits catalogados
38.524CVEs con explotación pública
24.695probados en laboratorio
82.322 exploits
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware23 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22518CRITICALbajo ataqueransomware23 ene 2024
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-0204CRITICAL23 ene 2024
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-0204CRITICAL23 ene 2024
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir ↗
GitHub PoC★ 7
Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898
CVE-2024-23897CRITICALbajo ataqueransomware23 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC
Shimon03/CVE-2023-7028-Account-Take-Over-Gitlab
CVE-2023-7028CRITICALbajo ataque23 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque22 ene 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗
GitHub PoC★ 5
thanhlam-attt/CVE-2023-22527
CVE-2023-22527CRITICALbajo ataqueransomware22 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
GitHub PoC★ 2
Drun1baby/CVE-2023-22527
CVE-2023-22527CRITICALbajo ataqueransomware22 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-28252HIGHbajo ataqueransomware22 ene 2024
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir ↗
GitHub PoC
BurakSevben/CVE-2024-24142
CVE-2024-24142CRITICAL22 ene 2024
Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.
48RIESGO
abrir ↗
GitHub PoC
Different files for computer security coursework
CVE-2021-3156HIGHbajo ataque22 ene 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware22 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware22 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware22 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
GitHub PoC★ 55
A modification to fortra's CVE-2023-28252 exploit, compiled to exe
CVE-2023-28252HIGHbajo ataqueransomware22 ene 2024
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir ↗
Metasploit600
Fortra GoAnywhere MFT Unauthenticated Remote Code Execution
CVE-2024-0204CRITICAL22 ene 2024
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir ↗
GitHub PoC
BurakSevben/CVE-2024-24141
CVE-2024-24141CRITICAL21 ene 2024
Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.
48RIESGO
abrir ↗
GitHub PoC★ 8
Repository containing a Proof of Concept (PoC) demonstrating the impact of CVE-2023-4911, a vulnerability in glibc's ld.so dynamic loader, exposing risks related to Looney Tunables.
CVE-2023-4911HIGHbajo ataque20 ene 2024
Glibc: buffer overflow in ld.so leading to privilege escalation
98RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-4911HIGHbajo ataque20 ene 2024
Glibc: buffer overflow in ld.so leading to privilege escalation
98RIESGO
abrir ↗
GitHub PoC★ 12
Mitigation validation utility for the Ivanti Connect Around attack chain. Runs multiple checks. CVE-2023-46805, CVE-2024-21887.
CVE-2024-21887CRITICALbajo ataqueransomware19 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗
GitHub PoC★ 14
Ivanti Pulse Secure CVE-2023-46805 Scanner - Based on Assetnote's Research
CVE-2023-46805HIGHbajo ataqueransomware19 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-46805HIGHbajo ataqueransomware19 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-46805HIGHbajo ataqueransomware19 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-46805HIGHbajo ataqueransomware19 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-4911HIGHbajo ataque19 ene 2024
Glibc: buffer overflow in ld.so leading to privilege escalation
98RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46805HIGHbajo ataqueransomware19 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-21887CRITICALbajo ataqueransomware19 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-21887CRITICALbajo ataqueransomware19 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗
GitHub PoC★ 12
Mitigation validation utility for the Ivanti Connect Around attack chain. Runs multiple checks. CVE-2023-46805, CVE-2024-21887.
CVE-2023-46805HIGHbajo ataqueransomware19 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
← anteriorpágina 504 / 2745siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.