Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
77.302 exploits
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware02 ago 2023
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC
overgrowncarrot1/DejaVu-CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware02 ago 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-2033HIGHbajo ataque02 ago 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALbajo ataque02 ago 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware02 ago 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864602 ago 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
GitHub PoC1
CVE-2020-0688 modified exploit for Exchange 2010
CVE-2020-0688HIGHbajo ataqueransomware02 ago 2023
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC
726232111/CVE-2023-28252
CVE-2023-28252HIGHbajo ataqueransomware02 ago 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir
Metasploit600
Eramba (up to 3.19.1) Authenticated Remote Code Execution Module
CVE-2023-3625501 ago 2023
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrar
30RIESGO
abrir
GitHub PoC
Unauthenticated Command Injection in Cacti <= 1.2.22
CVE-2022-46169CRITICALbajo ataque01 ago 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC2
Nmap NSE script to dump / test Solarwinds CVE-2023-23333 vulnerability
CVE-2023-23333CRITICAL01 ago 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
GitHub PoC
CVE-2022-1388 - F5 Router RCE Replica
CVE-2022-1388CRITICALbajo ataqueransomware01 ago 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC1
Nmap script to exploit CVE-2023-35078 - Mobile Iron Core
CVE-2023-35078CRITICALbajo ataqueransomware01 ago 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware01 ago 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23333CRITICAL01 ago 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque01 ago 2023
Unauthenticated Command Injection
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-35078CRITICALbajo ataqueransomware01 ago 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
GitHub PoC14
Mehran-Seifalinia/CVE-2023-37979
CVE-2023-37979HIGH01 ago 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque31 jul 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
GeoServer OGC Filter SQL Injection Vulnerabilities
CVE-2023-25157CRITICAL31 jul 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL31 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-35078CRITICALbajo ataqueransomware31 jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
GitHub PoC3
Perform With Mass Remote Code Execution In SPIP Version (4.2.1)
CVE-2023-27372CRITICAL31 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864631 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
Metasploit600
RaspAP Unauthenticated Command Injection
CVE-2022-3998631 jul 2023
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary comma
60RIESGO
abrir
Metasploit600
Maltrail Unauthenticated Command Injection
CVE-2025-34073CRITICAL31 jul 2023
stamparm/maltrail <=0.54 Remote Command Execution
63RIESGO
abrir
GitHub PoC5
Tools to scanner & exploit cve-2023-35078
CVE-2023-35078CRITICALbajo ataqueransomware31 jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
GitHub PoC
timsonner/cve-2014-0160-heartbleed
CVE-2014-0160HIGHbajo ataque31 jul 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
Easy and non-intrusive script to check for CVE-2023-35078
CVE-2023-35078CRITICALbajo ataqueransomware31 jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
Exploit-DBVexDay Proof
Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)
CVE-2023-39147webappsphp31 jul 2023
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafte
23RIESGO
abrir
anteriorpágina 477 / 2577siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.