Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
77.401 exploits
Exploit-DBVexDay Proof
Online Security Guards Hiring System 1.0 - Reflected XSS
CVE-2023-0527LOWwebappsphp31 may 2023
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RIESGO
abrir
Exploit-DBVexDay Proof
Faculty Evaluation System 1.0 - Unauthenticated File Upload
CVE-2023-33440HIGHwebappsphp31 may 2023
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u
61RIESGO
abrir
GitHub PoC1
Exploit for CVE:2010-2075. This exploit allows remote command execution in UnrealIRCd 3.2.8.1.
CVE-2010-207531 may 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
Exploit-DB
unilogies/bumsys v1.0.3 beta - Unrestricted File Upload
CVE-2023-0455HIGHwebappsphp31 may 2023
Unrestricted Upload of File with Dangerous Type in unilogies/bumsys
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware30 may 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC
the proof of concept written in Python for an unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. This is a critical severity issue
CVE-2023-2825CRITICAL30 may 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
GitHub PoC62
I5N0rth/CVE-2023-33246
CVE-2023-33246CRITICALbajo ataque30 may 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-1675HIGHbajo ataqueransomware30 may 2023
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALbajo ataque30 may 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC1
eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's password in plain text.
CVE-2023-33730CRITICAL30 may 2023
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL29 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC6
WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.
CVE-2020-0796CRITICALbajo ataqueransomware29 may 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC8
The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.
CVE-2019-905329 may 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALbajo ataqueransomware29 may 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-21839HIGHbajo ataque29 may 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
GitHub PoC
kw3h4/CVE-2023-21839-metasploit-scanner
CVE-2023-21839HIGHbajo ataque29 may 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
GitHub PoC2
Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...
CVE-2023-32243CRITICAL29 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
Metasploit600
Dolibarr ERP/CRM Authenticated Code Injection
CVE-2023-30253HIGH29 may 2023
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instea
58RIESGO
abrir
GitHub PoC1
MinIO Information Disclosure Vulnerability scanner by metasploit
CVE-2023-28432HIGHbajo ataque27 may 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque27 may 2023
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC2
Perfom With Massive Authentication Bypass In PaperCut MF/NG
CVE-2023-27350CRITICALbajo ataqueransomware27 may 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC2
Exploit for Bad Binder
CVE-2019-2215HIGHbajo ataque27 may 2023
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-28432HIGHbajo ataque27 may 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC1
PoC for login with password hash in STARFACE
CVE-2023-33243HIGH26 may 2023
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque26 may 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC2
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp
CVE-2022-22947CRITICALbajo ataque26 may 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
Metasploit600
Openfire authentication bypass with RCE plugin
CVE-2023-32315HIGHbajo ataque26 may 2023
Openfire administration console authentication bypass
100RIESGO
abrir
Exploit-DBVexDay Proof
Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)
CVE-2023-30145CRITICALwebappsruby26 may 2023
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-133525 may 2023
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL25 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
anteriorpágina 495 / 2581siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.