Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
24.459 exploits
Exploit-DB
Splunk 9.0.5 - admin account take over
CVE-2023-32707HIGHwebappsmultiple09 oct 2023
‘edit_user’ Capability Privilege Escalation
78RIESGO
abrir
Exploit-DB
Clcknshop 1.0.0 - SQL Injection
CVE-2023-4708MEDIUMwebappsphp09 oct 2023
Infosoftbd Clcknshop GET Parameter all sql injection
45RIESGO
abrir
Exploit-DB
Minio 2022-07-29T19-40-48Z - Path traversal
CVE-2022-35919HIGHwebappsgo09 oct 2023
Authenticated requests for server update admin API allows path traversal in minio
53RIESGO
abrir
Exploit-DB
BoidCMS v2.0.0 - authenticated file upload vulnerability
CVE-2023-38836webappsphp09 oct 2023
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header t
60RIESGO
abrir
Exploit-DB
Media Library Assistant Wordpress Plugin - RCE and LFI
CVE-2023-4634CRITICALwebappsphp09 oct 2023
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
85RIESGO
abrir
Exploit-DB
Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
CVE-2023-4278HIGHwebappsphp09 oct 2023
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
41RIESGO
abrir
Exploit-DB
Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities
CVE-2023-34723remotehardware08 sep 2023
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information
23RIESGO
abrir
Exploit-DB
Wordpress Plugin Elementor 3.5.5 - Iframe Injection
CVE-2022-4953webappsphp08 sep 2023
Elementor < 3.5.5 - Iframe Injection
23RIESGO
abrir
Exploit-DB
Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS
CVE-2022-31470webappsmultiple08 sep 2023
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12
50RIESGO
abrir
Exploit-DB
SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
CVE-2023-4548MEDIUMwebappsphp08 sep 2023
SPA-Cart eCommerce CMS GET Parameter search sql injection
38RIESGO
abrir
Exploit-DB
Hyip Rio 2.1 - Arbitrary File Upload
CVE-2023-4382LOWwebappsphp04 sep 2023
tdevs Hyip Rio Profile Settings settings cross site scripting
28RIESGO
abrir
Exploit-DB
Ivanti Avalanche <v6.4.0.0 - Remote Code Execution
CVE-2023-32560HIGHremotewindows04 sep 2023
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RIESGO
abrir
Exploit-DB
SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
CVE-2023-4547LOWwebappsphp04 sep 2023
SPA-Cart eCommerce CMS search cross site scripting
55RIESGO
abrir
Exploit-DB
FileMage Gateway 1.10.9 - Local File Inclusion
CVE-2023-39026webappsmultiple04 sep 2023
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
43RIESGO
abrir
Exploit-DB
WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)
CVE-2022-25148CRITICALwebappsphp04 sep 2023
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_id
85RIESGO
abrir
Exploit-DB
AdminLTE PiHole 5.18 - Broken Access Control
CVE-2022-23513MEDIUMwebappsphp04 sep 2023
Pi-Hole/AdminLTE vulnerable due to improper access control in queryads endpoint
45RIESGO
abrir
Exploit-DB
Credit Lite 1.5.4 - SQL Injection
CVE-2023-4407MEDIUMwebappsphp04 sep 2023
Codecanyon Credit Lite POST Request account_statement sql injection
33RIESGO
abrir
Exploit-DB
Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
CVE-2023-37759webappsphp21 ago 2023
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat
23RIESGO
abrir
Exploit-DB
TP-Link Archer AX21 - Unauthenticated Command Injection
CVE-2023-1389HIGHbajo ataqueremotehardware10 ago 2023
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RIESGO
abrir
Exploit-DB
Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
CVE-2023-4168MEDIUMwebappsphp08 ago 2023
Templatecookie Adlisting Redirect ad-list information disclosure
60RIESGO
abrir
Exploit-DB
Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
CVE-2023-29689webappspython08 ago 2023
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RIESGO
abrir
Exploit-DBVexDay Proof
mooSocial 3.1.8 - Reflected XSS
CVE-2023-4173LOWwebappsphp08 ago 2023
mooSocial mooStore index cross site scripting
43RIESGO
abrir
Exploit-DBVexDay Proof
Social-Commerce 3.1.6 - Reflected XSS
CVE-2023-4174LOWwebappsphp08 ago 2023
mooSocial mooStore cross site scripting
43RIESGO
abrir
Exploit-DB
Emagic Data Center Management Suite v6.0 - OS Command Injection
CVE-2023-37569HIGHwebappsphp08 ago 2023
OS Command Injection Vulnerability in Emagic Data Center Management Suite
53RIESGO
abrir
Exploit-DB
Shelly PRO 4PM v0.11.0 - Authentication Bypass
CVE-2023-33383remotehardware04 ago 2023
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RIESGO
abrir
Exploit-DB
PHPJabbers Night Club Booking 1.0 - Reflected XSS
CVE-2023-4114MEDIUMwebappsphp04 ago 2023
PHP Jabbers Night Club Booking Software index.php cross site scripting
48RIESGO
abrir
Exploit-DB
Academy LMS 6.0 - Reflected XSS
CVE-2023-4119MEDIUMwebappsphp04 ago 2023
Academy LMS courses cross site scripting
33RIESGO
abrir
Exploit-DB
WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
CVE-2023-37979HIGHwebappsphp04 ago 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RIESGO
abrir
Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
CVE-2023-3219webappsphp04 ago 2023
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RIESGO
abrir
Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
CVE-2023-2796webappsphp04 ago 2023
EventON < 2.1.2 - Unauthenticated Event Access
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.