Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
82.419 exploits
GitHub PoC★ 1
https://github.com/AbelChe/evil_minio/tree/main 打包留存
CVE-2023-28432HIGHbajo ataque26 nov 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗
GitHub PoC
working exploit for CVE-2019-9053
CVE-2019-9053—26 nov 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-38646—25 nov 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-2033HIGHbajo ataque24 nov 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RIESGO
abrir ↗
GitHub PoC★ 1
Exploit forCVE-2020-29607
CVE-2020-29607—24 nov 2023
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir ↗
GitHub PoC★ 1
Exploit for CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque23 nov 2023
Unauthenticated Command Injection
100RIESGO
abrir ↗
Metasploit600
WordPress Royal Elementor Addons RCE
CVE-2023-5360—23 nov 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque23 nov 2023
Unauthenticated Command Injection
100RIESGO
abrir ↗
GitHub PoC
By passing an overly large string when invoking nethack, it is possible to corrupt memory. jnethack and falconseye are also prone to this vulnerability.
CVE-2003-0358—22 nov 2023
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allow
23RIESGO
abrir ↗
GitHub PoC
exploit for cve-2023-47246 SysAid RCE (shell upload)
CVE-2023-47246CRITICALbajo ataqueransomware22 nov 2023
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a f
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-49103CRITICALbajo ataque22 nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-47246CRITICALbajo ataqueransomware22 nov 2023
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a f
100RIESGO
abrir ↗
GitHub PoC★ 2
A1Lin/cve-2022-1364
CVE-2022-1364HIGHbajo ataque22 nov 2023
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-1364HIGHbajo ataque22 nov 2023
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RIESGO
abrir ↗
GitHub PoC★ 30
PoC for the CVE-2023-49103
CVE-2023-49103CRITICALbajo ataque22 nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RIESGO
abrir ↗
GitHub PoC
Firewall rules to mitigate a zero-day vulnerability malware attack (CVE-2022-22965), known as Spring4Shell
CVE-2022-22965CRITICALbajo ataque21 nov 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware21 nov 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
GitHub PoC
Iris288/CVE-2021-43798
CVE-2021-43798HIGHbajo ataque21 nov 2023
Grafana path traversal
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque21 nov 2023
Grafana path traversal
100RIESGO
abrir ↗
Metasploit300
ownCloud Phpinfo Reader
CVE-2023-49103CRITICALbajo ataque21 nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RIESGO
abrir ↗
GitHub PoC
Log4Shell (CVE-2021-44228) minecraft demo. Used for education fairs
CVE-2021-44228CRITICALbajo ataqueransomware21 nov 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
GitHub PoC
CVE-2023-46604
CVE-2023-46604CRITICALbajo ataqueransomware20 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
GitHub PoC★ 1
PY
CVE-2023-46604CRITICALbajo ataqueransomware20 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
GitHub PoC
Polkit提权包 CVE-2021-4034 (供需要的人方便使用
CVE-2021-4034HIGHbajo ataqueransomware20 nov 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
GitHub PoC
Scripts to get infos
CVE-2023-4966CRITICALbajo ataqueransomware20 nov 2023
Unauthenticated sensitive information disclosure
100RIESGO
abrir ↗
GitHub PoC
Improved code of Daniele Scanu SQL Injection exploit
CVE-2019-9053—20 nov 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗
GitHub PoC
nitzanoligo/CVE-2023-46604-demo
CVE-2023-46604CRITICALbajo ataqueransomware20 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
GitHub PoC★ 2
CVE-2017-8917 SQL injection Vulnerability in Joomla! 3.7.0 exploit
CVE-2017-8917—20 nov 2023
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware20 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware20 nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
← anteriorpágina 524 / 2748siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.