Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
77.302 exploits
VulnCheck XDB
denial-of-service
CVE-2023-27997CRITICALbajo ataqueransomware23 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC
puckiestyle/cve-2023-27997
CVE-2023-27997CRITICALbajo ataqueransomware23 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC1
Windows Network File System Remote exploit (DoS) PoC
CVE-2022-30136CRITICAL23 jun 2023
Windows Network File System Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC10
An exploit for CVE-2018-5955 GitStack 2.3.10 Unauthenticated RCE
CVE-2018-595523 jun 2023
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-3614422 jun 2023
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to downlo
50RIESGO
abrir
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47076HIGHwebappsaspx22 jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-27997CRITICALbajo ataqueransomware22 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC1
imbas007/CVE-2023-27997-Check
CVE-2023-27997CRITICALbajo ataqueransomware22 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47075HIGHwebappsaspx22 jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RIESGO
abrir
GitHub PoC
sonpt-afk/CVE-2018-11776-FIS
CVE-2018-11776HIGHbajo ataque21 jun 2023
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC34
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
CVE-2022-42475CRITICALbajo ataqueransomware21 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque21 jun 2023
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-42475CRITICALbajo ataqueransomware21 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-1454MEDIUM20 jun 2023
jeecg-boot qurestSql sql injection
60RIESGO
abrir
Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
CVE-2023-25187MEDIUMremotehardware20 jun 2023
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque20 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC19
Exploits for a heap overflow in MiniDLNA <=1.3.2 (CVE-2023-33476)
CVE-2023-33476CRITICAL20 jun 2023
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by
48RIESGO
abrir
GitHub PoC2
Analysis & Exploit
CVE-2023-22809HIGH20 jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-2868CRITICALbajo ataque20 jun 2023
Remote Code injection in Barracuda Email Security Gateway
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque20 jun 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-22809HIGH20 jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
Exploit-DB
WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
CVE-2023-3320MEDIUMwebappsphp20 jun 2023
The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,
33RIESGO
abrir
Exploit-DBVexDay Proof
Super Socializer 7.13.52 - Reflected XSS
CVE-2023-2779MEDIUMwebappsphp20 jun 2023
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Exploit-DBVexDay Proof
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
CVE-2023-27372CRITICALwebappsphp20 jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC11
cfielding-r7/poc-cve-2023-2868
CVE-2023-2868CRITICALbajo ataque20 jun 2023
Remote Code injection in Barracuda Email Security Gateway
100RIESGO
abrir
GitHub PoC2
PoC and exploit for CVE-2022-22965 Spring4Shell
CVE-2022-22965CRITICALbajo ataque20 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC2
POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability
CVE-2022-0847HIGHbajo ataque20 jun 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC1
Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info
CVE-2021-42013CRITICALbajo ataqueransomware20 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Exploit-DB
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
CVE-2023-23956MEDIUMwebappshardware19 jun 2023
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RIESGO
abrir
GitHub PoC
overgrowncarrot1/CVE-2021-22911
CVE-2021-2291119 jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
anteriorpágina 487 / 2577siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.