Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
77.231 exploits
VulnCheck XDB
initial-access
CVE-2023-36847MEDIUMbajo ataque24 sep 2023
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-36844MEDIUMbajo ataque24 sep 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RIESGO
abrir
GitHub PoC
DimaMend/cve-2022-42889-text4shell
CVE-2022-4288922 sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-34753HIGH22 sep 2023
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288922 sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC3
Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE-2023-38831HIGHbajo ataqueransomware21 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC316
mistymntncop/CVE-2023-4863
CVE-2023-4863HIGHbajo ataque21 sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-39361CRITICAL21 sep 2023
Unauthenticated SQL Injection in graph_view.php in Cacti
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM21 sep 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-38831HIGHbajo ataqueransomware21 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-4863HIGHbajo ataque21 sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC1
A PoC for CVE-2022-26134 for Educational Purposes and Security Research
CVE-2022-26134CRITICALbajo ataqueransomware20 sep 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware20 sep 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC
Perform With Massive Juniper Remote Code Execution
CVE-2023-36844MEDIUMbajo ataque20 sep 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-36844MEDIUMbajo ataque20 sep 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RIESGO
abrir
Metasploit600
JetBrains TeamCity Unauthenticated Remote Code Execution
CVE-2023-42793CRITICALbajo ataqueransomware19 sep 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque17 sep 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-2640HIGH17 sep 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware17 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC1
CVE: CVE-2022-0847
CVE-2022-0847HIGHbajo ataque17 sep 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware17 sep 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
ngothienan/CVE-2023-38831
CVE-2023-38831HIGHbajo ataqueransomware17 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-32629HIGH17 sep 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2011-319216 sep 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RIESGO
abrir
GitHub PoC62
A go-exploit to scan for Juniper firewalls vulnerable to CVE-2023-36845
CVE-2023-36845CRITICALbajo ataque16 sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC
futurezayka/CVE-2011-3192
CVE-2011-319216 sep 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RIESGO
abrir
VulnCheck XDB
local
CVE-2023-36845CRITICALbajo ataque16 sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4060CRITICAL15 sep 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RIESGO
abrir
GitHub PoC5
WAGO Remote Exploit Tool for CVE-2023-1698
CVE-2023-1698CRITICAL15 sep 2023
WAGO: WBM Command Injection in multiple products
85RIESGO
abrir
GitHub PoC8
Automatic Mass Tool for checking vulnerability in CVE-2022-4060 - WordPress Plugin : User Post Gallery <= 2.19 - Unauthenticated RCE
CVE-2022-4060CRITICAL15 sep 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RIESGO
abrir
anteriorpágina 464 / 2575siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.