Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.451exploits catalogados
38.590CVEs con explotación pública
24.695probados en laboratorio
82.451 exploits
GitHub PoC★ 8
A PoC for CVE 2023-20198
CVE-2023-20198CRITICALbajo ataque23 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗
GitHub PoC★ 112
Exploit for CVE-2023-36802 targeting MSKSSRV.SYS driver
CVE-2023-36802HIGHbajo ataque23 oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RIESGO
abrir ↗
GitHub PoC★ 42
CVE-2013-4786 Go exploitation tool
CVE-2013-4786—23 oct 2023
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-36802HIGHbajo ataque23 oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque23 oct 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-38646—23 oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗
GitHub PoC
Python script get image from Hikvision camera with CVE-2017-7921 vulnerability
CVE-2017-7921CRITICALbajo ataque23 oct 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque22 oct 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware22 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-33044CRITICALbajo ataque22 oct 2023
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir ↗
GitHub PoC★ 1
haingn/HIK-CVE-2021-36260-Exploit
CVE-2021-36260CRITICALbajo ataque22 oct 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗
GitHub PoC★ 3
haingn/LoHongCam-CVE-2021-33044
CVE-2021-33044CRITICALbajo ataque22 oct 2023
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir ↗
GitHub PoC
banyaksepuh/Mass-CVE-2021-3129-Scanner
CVE-2021-3129CRITICALbajo ataqueransomware22 oct 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗
GitHub PoC
Nielk74/CVE-2023-38831
CVE-2023-38831HIGHbajo ataqueransomware21 oct 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗
GitHub PoC
ShivamDey/Samba-CVE-2007-2447-Exploit
CVE-2007-2447—21 oct 2023
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗
GitHub PoC
cve-2023-22515的python利用脚本
CVE-2023-22515CRITICALbajo ataqueransomware21 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗
GitHub PoC★ 3
CVE-2023-5360 Auto Shell Upload WordPress Royal Elementor 1.3.78 Shell Upload
CVE-2023-5360—21 oct 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware21 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗
GitHub PoC
ShivamDey/CVE-2021-23017
CVE-2021-23017—21 oct 2023
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir ↗
GitHub PoC
yTxZx/CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque20 oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗
GitHub PoC
reket99/Cisco_CVE-2023-20198
CVE-2023-20198CRITICALbajo ataque20 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-28432HIGHbajo ataque20 oct 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗
GitHub PoC★ 3
yTxZx/CVE-2023-28432
CVE-2023-28432HIGHbajo ataque20 oct 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗
GitHub PoC★ 6
1vere$k POC on the CVE-2023-20198
CVE-2023-20198CRITICALbajo ataque20 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware20 oct 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗
GitHub PoC★ 4
CISCO CVE POC SCRIPT
CVE-2023-20198CRITICALbajo ataque20 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗
GitHub PoC★ 20
Confluence后台rce
CVE-2023-22515CRITICALbajo ataqueransomware20 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗
GitHub PoC★ 36
PoC for CVE-2023-36802 Microsoft Kernel Streaming Service Proxy
CVE-2023-36802HIGHbajo ataque20 oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RIESGO
abrir ↗
GitHub PoC
Trinadh465/frameworks_base_AOSP10_r33_CVE-2023-20963
CVE-2023-20963HIGHbajo ataque20 oct 2023
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RIESGO
abrir ↗
GitHub PoC
yTxZx/CVE-2022-26134
CVE-2022-26134CRITICALbajo ataqueransomware20 oct 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗
← anteriorpágina 533 / 2749siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.