Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
82.419 exploits
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALbajo ataque15 dic 2023
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir ↗
GitHub PoC
ZhiQiAnSecFork/DirtyCOW_CVE-2016-5195
CVE-2016-5195HIGHbajo ataque15 dic 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque15 dic 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗
Metasploit600
MajorDoMo Command Injection
CVE-2023-50917—15 dic 2023
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RIESGO
abrir ↗
GitHub PoC
CVE-2022-4047 poc
CVE-2022-4047CRITICAL14 dic 2023
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir ↗
GitHub PoC★ 5
Exihibitor Web Ui 1.7.1 RCE, CVE-2019-5029
CVE-2019-5029CRITICAL14 dic 2023
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7
60RIESGO
abrir ↗
GitHub PoC★ 1
imperva/CVE-2023-22524
CVE-2023-22524CRITICAL14 dic 2023
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An att
53RIESGO
abrir ↗
GitHub PoC★ 25
Atlassian Companion RCE Vulnerability Proof of Concept
CVE-2023-22524CRITICAL14 dic 2023
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An att
53RIESGO
abrir ↗
GitHub PoC★ 2
SQL Injection in 3CX CRM Integration
CVE-2023-49954CRITICAL14 dic 2023
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search stri
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-49070—14 dic 2023
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-6553CRITICAL13 dic 2023
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque13 dic 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗
GitHub PoC
mareks1007/cve-2017-16995
CVE-2017-16995—13 dic 2023
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗
GitHub PoC
CVE-2023-23752 Joomla Unauthenticated Information Disclosure
CVE-2023-23752MEDIUMbajo ataque13 dic 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-32629HIGH13 dic 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
56RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-2640HIGH13 dic 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RIESGO
abrir ↗
GitHub PoC★ 86
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
CVE-2023-6553CRITICAL13 dic 2023
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir ↗
GitHub PoC★ 9
CVE-2021-40438 Apache <= 2.4.48 SSRF exploit
CVE-2021-40438CRITICALbajo ataqueransomware12 dic 2023
mod_proxy SSRF
100RIESGO
abrir ↗
GitHub PoC★ 1
CVE-2023-38831 Proof-of-concept code
CVE-2023-38831HIGHbajo ataqueransomware12 dic 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-40438CRITICALbajo ataqueransomware12 dic 2023
mod_proxy SSRF
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2020-1472MEDIUMbajo ataqueransomware12 dic 2023
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir ↗
GitHub PoC
RCE for Webmin CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware12 dic 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware12 dic 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware12 dic 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALbajo ataque11 dic 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗
Metasploit600
WordPress Backup Migration Plugin PHP Filter Chain RCE
CVE-2023-6553CRITICAL11 dic 2023
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir ↗
GitHub PoC
hadrian3689/CVE-2023-23752_Joomla
CVE-2023-23752MEDIUMbajo ataque11 dic 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque11 dic 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗
GitHub PoC★ 2
Cisco CVE-2023-20198
CVE-2023-20198CRITICALbajo ataque11 dic 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHbajo ataque11 dic 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir ↗
← anteriorpágina 520 / 2748siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.