Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
77.401 exploits
VulnCheck XDB
initial-access
CVE-2019-908125 abr 2023
20RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-22621CRITICAL25 abr 2023
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RIESGO
abrir
GitHub PoC
2022 Spring Prof. 謝續平
CVE-2022-21907CRITICAL25 abr 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALbajo ataqueransomware25 abr 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC
ShyTangerine/cve-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware25 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27524HIGHbajo ataque25 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-41277CRITICALbajo ataque24 abr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
Metasploit600
Ivanti Avalanche FileStoreConfig File Upload
CVE-2023-28128HIGH24 abr 2023
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could
58RIESGO
abrir
GitHub PoC1
RubXkuB/PoC-Metabase-CVE-2021-41277
CVE-2021-41277CRITICALbajo ataque24 abr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
Metasploit600
invscout RPM Privilege Escalation
CVE-2023-28528HIGH24 abr 2023
IBM AIX command execution
36RIESGO
abrir
GitHub PoC13
CVE-2023-22894
CVE-2023-22894CRITICAL24 abr 2023
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RIESGO
abrir
GitHub PoC16
CVE-2023-1671-POC, based on dnslog platform
CVE-2023-1671CRITICALbajo ataque24 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
GitHub PoC
andyhsu024/CVE-2021-29447
CVE-2021-29447HIGH24 abr 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALbajo ataque24 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
GitHub PoC
msd0pe-1/CVE-2023-31747
CVE-2023-31747HIGH24 abr 2023
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALbajo ataque23 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALbajo ataqueransomware23 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-40799HIGHbajo ataque23 abr 2023
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l
83RIESGO
abrir
GitHub PoC1
glen-pearson/ProxyLogon-CVE-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware23 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
Pre-Auth RCE in Sophos Web Appliance
CVE-2023-1671CRITICALbajo ataque23 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
GitHub PoC1
Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.
CVE-2022-1609CRITICAL22 abr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALbajo ataqueransomware22 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1609CRITICAL22 abr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir
GitHub PoC55
Proof of Concept Exploit for PaperCut CVE-2023-27350
CVE-2023-27350CRITICALbajo ataqueransomware22 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC2
「💥」CVE-2022-4944: KodExplorer <= 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUM21 abr 2023
kalcaddle KodExplorer cross-site request forgery
33RIESGO
abrir
Metasploit300
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
CVE-2023-26876HIGH21 abr 2023
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via t
36RIESGO
abrir
GitHub PoC12
imancybersecurity/CVE-2023-27350-POC
CVE-2023-27350CRITICALbajo ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC
Anonimo501/ssh_enum_users_CVE-2018-15473
CVE-2018-15473MEDIUM21 abr 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-1454MEDIUM21 abr 2023
jeecg-boot qurestSql sql injection
60RIESGO
abrir
GitHub PoC5
A simple python script to check if a service is vulnerable
CVE-2023-27350CRITICALbajo ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
anteriorpágina 504 / 2581siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.