Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.322exploits catalogados
38.524CVEs con explotación pública
24.695probados en laboratorio
82.322 exploits
VulnCheck XDB
initial-access
CVE-2024-21887CRITICALbajo ataqueransomware19 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-46805HIGHbajo ataqueransomware18 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque18 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC★ 5
The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.
CVE-2023-46805HIGHbajo ataqueransomware18 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
GitHub PoC★ 5
The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.
CVE-2024-21887CRITICALbajo ataqueransomware18 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗
GitHub PoC★ 4
CVE-2023-7028 killer
CVE-2023-7028CRITICALbajo ataque18 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC
Exploit for CVE-2023-7028 - GitLab CE/EE
CVE-2023-7028CRITICALbajo ataque18 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC
Exploit for KNet 1.04b Web Server Buffer Overflow SEH
CVE-2005-0575—18 ene 2024
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-22274—18 ene 2024
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to
45RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware17 ene 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2024-22145HIGH17 ene 2024
WordPress InstaWP Connect plugin <= 0.1.0.8 - Arbitrary Option Update to Privilege Escalation vulnerability
41RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-51467—17 ene 2024
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-52076HIGH17 ene 2024
Remote Code Execution Vulnerability in Atril's EPUB ebook parsing
41RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMbajo ataque17 ene 2024
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir ↗
GitHub PoC★ 1
A one-click script to gain a System privileges command line in Windows 10 20H2 that exploits CVE-2021-1675
CVE-2021-1675HIGHbajo ataqueransomware17 ene 2024
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC
PoC de Polkit
CVE-2021-4034HIGHbajo ataqueransomware17 ene 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
GitHub PoC★ 4
This is a fix POC CVE-2020-11651 & CVE-2020-11651
CVE-2020-11652MEDIUMbajo ataque17 ene 2024
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque17 ene 2024
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-6895MEDIUM17 ene 2024
Hikvision Intercom Broadcasting System ping.php os command injection
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-49070—17 ene 2024
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir ↗
GitHub PoC
Exploit information for CVE-2023-26602
CVE-2023-26602—16 ene 2024
ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create exten
28RIESGO
abrir ↗
GitHub PoC
Pol-Ruiz/CVE-2021-4034
CVE-2021-4034HIGHbajo ataqueransomware16 ene 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
Metasploit600
Atlassian Confluence SSTI Injection
CVE-2023-22527CRITICALbajo ataqueransomware16 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-26609HIGH16 ene 2024
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RIESGO
abrir ↗
GitHub PoC
Exploit information for CVE-2023-26609
CVE-2023-26609HIGH16 ene 2024
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware16 ene 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
GitHub PoC★ 26
CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server PoC
CVE-2023-22527CRITICALbajo ataqueransomware16 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗
GitHub PoC★ 5
Simple scanner for scanning a list of ip-addresses for vulnerable Ivanti Pulse Secure devices
CVE-2023-46805HIGHbajo ataqueransomware16 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46805HIGHbajo ataqueransomware16 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
GitHub PoC★ 23
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
CVE-2024-21887CRITICALbajo ataqueransomware16 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗
← anteriorpágina 505 / 2745siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.