Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.322exploits catalogados
38.524CVEs con explotación pública
24.695probados en laboratorio
82.322 exploits
GitHub PoC★ 5
Simple scanner for scanning a list of ip-addresses for vulnerable Ivanti Pulse Secure devices
CVE-2023-46805HIGHbajo ataqueransomware16 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
GitHub PoC
Exploit information for CVE-2023-26609
CVE-2023-26609HIGH16 ene 2024
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware15 ene 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2016-4437CRITICALbajo ataque15 ene 2024
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗
GitHub PoC
Proof of Concept script to exploit CVE-2023-42793 (TeamCity)
CVE-2023-42793CRITICALbajo ataqueransomware15 ene 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-35813—15 ene 2024
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware15 ene 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗
GitHub PoC★ 5
CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware15 ene 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗
GitHub PoC
1.验证CVE-2016-4437、2.解析rememberMe的文件和CBC加密的IV偏移
CVE-2016-4437CRITICALbajo ataque15 ene 2024
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-46805HIGHbajo ataqueransomware14 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-21887CRITICALbajo ataqueransomware14 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗
GitHub PoC★ 10
Scanner for CVE-2023-46805 - Ivanti Connect Secure
CVE-2023-46805HIGHbajo ataqueransomware14 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗
GitHub PoC★ 7
POC Checker for ivanti CVE-2024-21887 Command injcetion
CVE-2024-21887CRITICALbajo ataqueransomware14 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-51467—13 ene 2024
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-6875CRITICAL13 ene 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir ↗
GitHub PoC
Program ini adalah alat (tool) yang dibuat untuk memeriksa keamanan sistem Minio terkait dengan kerentanan CVE-2022-35919
CVE-2022-35919HIGH13 ene 2024
Authenticated requests for server update admin API allows path traversal in minio
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC★ 245
This repository presents a proof-of-concept of CVE-2023-7028
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC
CVE-2023-7028 poc
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC★ 58
CVE-2023-7028
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC★ 3
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
CVE-2023-7028CRITICALbajo ataque12 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2023-0656—12 ene 2024
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of S
35RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-51467—11 ene 2024
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-49070—11 ene 2024
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir ↗
Metasploit300
GitLab Password Reset Account Takeover
CVE-2023-7028CRITICALbajo ataque11 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
Metasploit600
Netis router MW5360 unauthenticated RCE.
CVE-2024-22729CRITICAL11 ene 2024
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter
65RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-6567CRITICAL11 ene 2024
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
75RIESGO
abrir ↗
← anteriorpágina 506 / 2745siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.