Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
82.419 exploits
Metasploit600
Barracuda ESG Spreadsheet::ParseExcel Arbitrary Code Execution
CVE-2023-7102—24 dic 2023
Remote Code Execution (RCE) Vulnerability
30RIESGO
abrir ↗
Metasploit600
Barracuda ESG Spreadsheet::ParseExcel Arbitrary Code Execution
CVE-2023-7101HIGHbajo ataque24 dic 2023
Arbitrary Code Execution (ACE) Vulnerability
71RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-0386HIGHbajo ataque23 dic 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware23 dic 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-4911HIGHbajo ataque23 dic 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
98RIESGO
abrir ↗
GitHub PoC
CVE-2023-46604 - ApacheMQ Version 5.15.5 Vulnerability Machine: Broker
CVE-2023-46604CRITICALbajo ataqueransomware23 dic 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
GitHub PoC★ 2
puckiestyle/CVE-2023-4911
CVE-2023-4911HIGHbajo ataque23 dic 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
98RIESGO
abrir ↗
GitHub PoC★ 18
puckiestyle/CVE-2023-0386
CVE-2023-0386HIGHbajo ataque23 dic 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2016-4437CRITICALbajo ataque22 dic 2023
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗
GitHub PoC★ 4
Guillaume-Risch/cve-2023-29357-Sharepoint
CVE-2023-29357CRITICALbajo ataqueransomware22 dic 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 2
Python POC to Exploit CVE-2016-4437 Apache Shiro Deserialization Vulnerability Due to Hardcode Encryption Key
CVE-2016-4437CRITICALbajo ataque22 dic 2023
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗
GitHub PoC★ 16
CVE-2023-50254: PoC Exploit for Deepin-reader RCE that affects unpatched Deepin Linux Desktops. Deepin Linux's default document reader "deepin-reader" software suffers from a serious vulnerability due to a design flaw that leads to Remote Command Execution via crafted docx document.
CVE-2023-50254CRITICAL22 dic 2023
Deepin Reader RCE vulnerability due to a design flaw
48RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque21 dic 2023
Grafana path traversal
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALbajo ataqueransomware21 dic 2023
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1040CRITICALbajo ataque21 dic 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-22941CRITICALbajo ataqueransomware21 dic 2023
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque21 dic 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-2109HIGH21 dic 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-2109HIGH21 dic 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque21 dic 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware21 dic 2023
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗
GitHub PoC★ 14
substing/CVE-2020-24186_reverse_shell_upload
CVE-2020-24186CRITICAL21 dic 2023
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2019-5736—21 dic 2023
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-22555HIGHbajo ataque21 dic 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2017-8917—21 dic 2023
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-25223CRITICALbajo ataque21 dic 2023
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2018-2628CRITICALbajo ataque21 dic 2023
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware21 dic 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-0230—21 dic 2023
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALbajo ataqueransomware21 dic 2023
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir ↗
← anteriorpágina 513 / 2748siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.