Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC3
CVE-2023-36845 - Juniper Firewall Remote code execution (RCE)
CVE-2023-36845CRITICALbajo ataque29 sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC
jytmX/CVE-2021-24499
CVE-2021-2449929 sep 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RIESGO
abrir
GitHub PoC
go CVE-2023-24538 patch issue resolver - Kirkstone
CVE-2023-24538CRITICAL29 sep 2023
Backticks not treated as string delimiters in html/template
48RIESGO
abrir
GitHub PoC
go CVE-2023-24538 patch issue resolver - Dunfell
CVE-2023-24538CRITICAL29 sep 2023
Backticks not treated as string delimiters in html/template
48RIESGO
abrir
GitHub PoC41
MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit
CVE-2023-36884HIGHbajo ataqueransomware28 sep 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC3
PoC for Stored XSS (CVE-2023-43770) Vulnerability
CVE-2023-43770MEDIUMbajo ataque28 sep 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RIESGO
abrir
GitHub PoC34
A Proof-Of-Concept for the CVE-2023-43770 vulnerability.
CVE-2023-43770MEDIUMbajo ataque27 sep 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RIESGO
abrir
GitHub PoC1
halencarjunior/CVE-2023-36845
CVE-2023-36845CRITICALbajo ataque27 sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC9
CVE-2023-34152
CVE-2023-34152CRITICAL27 sep 2023
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob wit
48RIESGO
abrir
GitHub PoC24
buptsb/CVE-2023-4762
CVE-2023-4762HIGHbajo ataque27 sep 2023
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a
83RIESGO
abrir
GitHub PoC
sherlocksecurity/CVE-2023-4762-Code-Review
CVE-2023-4762HIGHbajo ataque27 sep 2023
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a
83RIESGO
abrir
GitHub PoC1
Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4047 - Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
CVE-2022-4047CRITICAL26 sep 2023
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
GitHub PoC239
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-29357CRITICALbajo ataqueransomware26 sep 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
New exploitation of 2020 Sophos vuln
CVE-2022-1040CRITICALbajo ataque26 sep 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RIESGO
abrir
GitHub PoC55
Juniper Firewalls CVE-2023-36845 - RCE
CVE-2023-36845CRITICALbajo ataque26 sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC8
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
CVE-2023-20887CRITICALbajo ataque25 sep 2023
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RIESGO
abrir
GitHub PoC3
BAD-WEBP-CVE-2023-4863
CVE-2023-4863HIGHbajo ataque25 sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC6
bbaranoff/CVE-2023-4863
CVE-2023-4863HIGHbajo ataque25 sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC5
A Proof of Concept for chaining the CVEs [CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, CVE-2023-36847] to achieve Remote Code Execution (phpinfo) in Juniper JunOS within SRX and EX Series products.Modified from original exploit developed by @watchTowr .
CVE-2023-36844MEDIUMbajo ataque24 sep 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RIESGO
abrir
GitHub PoC151
Exploit for CVE-2023-29360 targeting MSKSSRV.SYS driver
CVE-2023-29360HIGHbajo ataque24 sep 2023
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
DimaMend/cve-2022-42889-text4shell
CVE-2022-4288922 sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC316
mistymntncop/CVE-2023-4863
CVE-2023-4863HIGHbajo ataque21 sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC3
Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE-2023-38831HIGHbajo ataqueransomware21 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
Perform With Massive Juniper Remote Code Execution
CVE-2023-36844MEDIUMbajo ataque20 sep 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RIESGO
abrir
GitHub PoC1
A PoC for CVE-2022-26134 for Educational Purposes and Security Research
CVE-2022-26134CRITICALbajo ataqueransomware20 sep 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
CVE: CVE-2022-0847
CVE-2022-0847HIGHbajo ataque17 sep 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
ngothienan/CVE-2023-38831
CVE-2023-38831HIGHbajo ataqueransomware17 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC62
A go-exploit to scan for Juniper firewalls vulnerable to CVE-2023-36845
CVE-2023-36845CRITICALbajo ataque16 sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC
futurezayka/CVE-2011-3192
CVE-2011-319216 sep 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RIESGO
abrir
GitHub PoC5
WAGO Remote Exploit Tool for CVE-2023-1698
CVE-2023-1698CRITICAL15 sep 2023
WAGO: WBM Command Injection in multiple products
85RIESGO
abrir
anteriorpágina 258 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.