Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.444exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
77.401 exploits
GitHub PoC
On May 23, 2023 GitLab released version 16.0.1 which fixed a critical vulnerability, CVE-2023-2825, affecting the Community Edition (CE) and Enterprise Edition (EE) version 16.0.0. The vulnerability allows unauthenticated users to read arbitrary files through a path traversal bug.
CVE-2023-2825CRITICAL05 jun 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
GitHub PoC
Proof of concept / CTF script for exploiting CVE-2022-46169 in Cacti, versions >=1.2.22
CVE-2022-46169CRITICALbajo ataque05 jun 2023
Unauthenticated Command Injection
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware05 jun 2023
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution (RCE)
CVE-2023-2068webappsphp04 jun 2023
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RIESGO
abrir
VulnCheck XDB
local
CVE-2023-32784HIGH04 jun 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RIESGO
abrir
Exploit-DB
STARFACE 7.3.0.10 - Authentication with Password Hash Possible
CVE-2023-33243HIGHwebappsjsp04 jun 2023
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RIESGO
abrir
GitHub PoC
Exploit created in python3 to exploit known vulnerabilities in Apache web server (CVE-2021-41773, CVE-2021-42013)
CVE-2021-41773HIGHbajo ataqueransomware03 jun 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware03 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque03 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC3
Poc&Exp,支持批量扫描,反弹shell
CVE-2022-22965CRITICALbajo ataque03 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware03 jun 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC3
CVE-2023-33246:Apache RocketMQ 远程命令执行漏洞检测工具
CVE-2023-33246CRITICALbajo ataque02 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-044102 jun 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
GitHub PoC1
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
CVE-2022-044102 jun 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALbajo ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
Metasploit600
Splunk "edit_user" Capability Privilege Escalation
CVE-2023-32707HIGH01 jun 2023
‘edit_user’ Capability Privilege Escalation
78RIESGO
abrir
Metasploit600
Chamilo unauthenticated command injection in PowerPoint upload
CVE-2023-3496001 jun 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RIESGO
abrir
GitHub PoC
[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure
CVE-2021-33690CRITICAL01 jun 2023
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RIESGO
abrir
GitHub PoC81
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALbajo ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-33690CRITICAL01 jun 2023
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RIESGO
abrir
GitHub PoC114
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALbajo ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
Exploit-DB
Pydio Cells 4.1.2 - Unauthorised Role Assignments
CVE-2023-32749HIGHwebappsgo31 may 2023
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RIESGO
abrir
Exploit-DBVexDay Proof
Online Security Guards Hiring System 1.0 - Reflected XSS
CVE-2023-0527LOWwebappsphp31 may 2023
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RIESGO
abrir
Exploit-DB
unilogies/bumsys v1.0.3 beta - Unrestricted File Upload
CVE-2023-0455HIGHwebappsphp31 may 2023
Unrestricted Upload of File with Dangerous Type in unilogies/bumsys
41RIESGO
abrir
Exploit-DB
Pydio Cells 4.1.2 - Cross-Site Scripting (XSS) via File Download
CVE-2023-32751MEDIUMwebappsgo31 may 2023
Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are genera
33RIESGO
abrir
GitHub PoC2
4mazing/CVE-2023-33246-Copy
CVE-2023-33246CRITICALbajo ataque31 may 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
Exploit-DB
Pydio Cells 4.1.2 - Server-Side Request Forgery
CVE-2023-32750MEDIUMwebappsgo31 may 2023
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque31 may 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC2
A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability
CVE-2022-22965CRITICALbajo ataque31 may 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
Metasploit600
Wordpress File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution through shortcode
CVE-2023-206831 may 2023
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RIESGO
abrir
anteriorpágina 494 / 2581siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.