Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
77.302 exploits
VulnCheck XDB
initial-access
CVE-2023-3864609 ago 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-2503209 ago 2023
PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
38RIESGO
abrir
Metasploit600
PRTG CVE-2023-32781 Authenticated RCE
CVE-2023-3278109 ago 2023
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an au
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864609 ago 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
GitHub PoC
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
CVE-2021-34621CRITICAL09 ago 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM09 ago 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
Exploit-DB
Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
CVE-2023-29689webappspython08 ago 2023
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RIESGO
abrir
Exploit-DBVexDay Proof
Social-Commerce 3.1.6 - Reflected XSS
CVE-2023-4174LOWwebappsphp08 ago 2023
mooSocial mooStore cross site scripting
43RIESGO
abrir
Metasploit600
CrushFTP Unauthenticated RCE
CVE-2023-4317708 ago 2023
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes
60RIESGO
abrir
Exploit-DB
Emagic Data Center Management Suite v6.0 - OS Command Injection
CVE-2023-37569HIGHwebappsphp08 ago 2023
OS Command Injection Vulnerability in Emagic Data Center Management Suite
53RIESGO
abrir
Exploit-DBVexDay Proof
mooSocial 3.1.8 - Reflected XSS
CVE-2023-4173LOWwebappsphp08 ago 2023
mooSocial mooStore index cross site scripting
43RIESGO
abrir
Exploit-DB
Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
CVE-2023-4168MEDIUMwebappsphp08 ago 2023
Templatecookie Adlisting Redirect ad-list information disclosure
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-095207 ago 2023
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
43RIESGO
abrir
GitHub PoC
Original Exploit Source: https://www.exploit-db.com/exploits/46635
CVE-2019-905307 ago 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC9
CVE exploitation for WebKit jsc CVE-2018-4416
CVE-2018-441607 ago 2023
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-26067HIGH07 ago 2023
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
68RIESGO
abrir
GitHub PoC
Campcodes Online Matrimonial Website System 3.3 Cross Site Scripting
CVE-2023-3911507 ago 2023
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RIESGO
abrir
GitHub PoC
MrE-Fog/jboss-_CVE-2017-12149
CVE-2017-12149CRITICALbajo ataqueransomware06 ago 2023
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALbajo ataqueransomware06 ago 2023
Unauthenticated remote code execution
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-22809HIGH06 ago 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware06 ago 2023
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC1
rwincey/cve-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware06 ago 2023
Unauthenticated remote code execution
100RIESGO
abrir
GitHub PoC2
Running this exploit on a vulnerable system allows a local attacker to gain a root shell on the machine.
CVE-2023-22809HIGH06 ago 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC1
passwa11/CVE-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware05 ago 2023
Unauthenticated remote code execution
100RIESGO
abrir
GitHub PoC3
This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on Ubuntu 5.8.0-48-generic and COS 5.4.89+. Use responsibly and ethically.
CVE-2021-22555HIGHbajo ataque05 ago 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
GitHub PoC1
Quick PoC checker for common configurations that might be available via directory traversal due to CVE-2013-3827
CVE-2013-382705 ago 2023
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM05 ago 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
GitHub PoC2
Exim < 4.90.1 RCE Vulnerability remake for Python3 with arguments passed from CLI
CVE-2018-6789CRITICALbajo ataqueransomware05 ago 2023
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2013-382705 ago 2023
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-2732CRITICAL05 ago 2023
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
anteriorpágina 475 / 2577siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.