Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.745exploits catalogados
38.712CVEs con explotación pública
24.695probados en laboratorio
82.745 exploits
GitHub PoC★ 46
A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.
CVE-2017-7921CRITICALbajo ataque24 jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗
GitHub PoC★ 1
CVE-2022-23305 Log4J JDBCAppender SQl injection POC
CVE-2022-23305CRITICAL24 jul 2023
SQL injection in JDBC Appender in Apache Log4j V1
60RIESGO
abrir ↗
GitHub PoC★ 1
ImageMagick Arbitrary Read Files - CVE-2022-44268
CVE-2022-44268MEDIUM23 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-1177CRITICAL23 jul 2023
Path Traversal: '\..\filename' in mlflow/mlflow
75RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-34960—22 jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RIESGO
abrir ↗
Metasploit600
Metabase Setup Token RCE
CVE-2023-38646—22 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2021-22873—22 jul 2023
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg
50RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-4191MEDIUM22 jul 2023
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir ↗
GitHub PoC★ 1
NetScaler (Citrix ADC) CVE-2023-3519 Scanner
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir ↗
GitHub PoC★ 13
mr-r3b00t/CVE-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir ↗
GitHub PoC
CVE-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir ↗
GitHub PoC★ 228
RCE exploit for CVE-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir ↗
GitHub PoC★ 11
CVE-2023-3519 vuln for nuclei scanner
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware21 jul 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM20 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir ↗
Exploit-DB
RWS WorldServer 11.7.3 - Session Token Enumeration
CVE-2023-38357—webappsmultiple20 jul 2023
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a
23RIESGO
abrir ↗
GitHub PoC★ 52
Citrix Scanner for CVE-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware20 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir ↗
GitHub PoC★ 1
lakshit1212/CVE-2021-23017-PoC
CVE-2021-23017—20 jul 2023
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir ↗
GitHub PoC
passwa11/CVE-2023-29017-reverse-shell
CVE-2023-29017CRITICAL20 jul 2023
vm2 Sandbox Escape vulnerability
60RIESGO
abrir ↗
GitHub PoC★ 86
Accurately fingerprint and detect vulnerable (and patched!) versions of Netscaler / Citrix ADC to CVE-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware20 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir ↗
GitHub PoC
PowerShell Script for initial mitigation of vulnerability
CVE-2023-36884HIGHbajo ataqueransomware20 jul 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir ↗
Exploit-DB
pfSense v2.7.0 - OS Command Injection
CVE-2023-27253—webappsphp20 jul 2023
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attac
60RIESGO
abrir ↗
Exploit-DB
Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE.
CVE-2023-33148HIGHremotemultiple20 jul 2023
Microsoft Office Elevation of Privilege Vulnerability
41RIESGO
abrir ↗
GitHub PoC★ 2
A PoC exploit for CVE-2015-2166 - Directory Traversal Vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP)
CVE-2015-2166—20 jul 2023
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5
43RIESGO
abrir ↗
GitHub PoC★ 4
A PoC exploit for CVE-2010-4231 - Directory Traversal Vulnerability in Camtron and TecVoz IP Cameras.
CVE-2010-4231—20 jul 2023
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera an
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
CVE-2023-37629—webappsphp19 jul 2023
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send
43RIESGO
abrir ↗
Exploit-DB
ABB FlowX v4.00 - Exposure of Sensitive Information
CVE-2023-1258MEDIUMwebappshardware19 jul 2023
Flow-X disclosure of sensitive information to unauthenticated users
33RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM19 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir ↗
← anteriorpágina 562 / 2759siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.