Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
77.401 exploits
GitHub PoC2
DarokNET/CVE-2023-27100
CVE-2023-27100CRITICAL07 abr 2023
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RIESGO
abrir
Exploit-DB
Wondershare Dr Fone 12.9.6 - Privilege Escalation
CVE-2023-27010HIGHlocalwindows07 abr 2023
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all
41RIESGO
abrir
Exploit-DB
Docker based datastores for IBM Instana 241-2 243-0 - No Authentication
CVE-2023-27290CRITICALremotemultiple07 abr 2023
IBM Observability with Instana missing authentication
48RIESGO
abrir
Exploit-DB
Tenda N300 F3 12.01.01.48 - Malformed HTTP Request Header Processing
CVE-2020-35391CRITICALremotehardware07 abr 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RIESGO
abrir
Exploit-DB
NotrinosERP 0.7 - Authenticated Blind SQL Injection
CVE-2023-24788webappsphp07 abr 2023
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
23RIESGO
abrir
Exploit-DB
ChurchCRM 4.5.1 - Authenticated SQL Injection
CVE-2023-24787webappsphp07 abr 2023
20RIESGO
abrir
GitHub PoC
Checker help to verify created account or find it's mandat
CVE-2020-6287CRITICALbajo ataque07 abr 2023
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-21742HIGH07 abr 2023
Microsoft SharePoint Server Remote Code Execution Vulnerability
53RIESGO
abrir
Exploit-DB
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
CVE-2022-47986CRITICALbajo ataqueransomwareremotemultiple07 abr 2023
IBM Aspera Faspex code execution
100RIESGO
abrir
Exploit-DB
MAC 1200R - Directory Traversal
CVE-2021-27825HIGHwebappshardware07 abr 2023
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-stati
41RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-6287CRITICALbajo ataque07 abr 2023
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque07 abr 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
jedai47/cve-2018-17182
CVE-2018-1718207 abr 2023
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
GitHub PoC
jedai47/CVE-2018-7273
CVE-2018-727307 abr 2023
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RIESGO
abrir
GitHub PoC1
POC,EXP,chatGPT for me,只能给一些思路,全部不可用
CVE-2022-21306CRITICAL07 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
48RIESGO
abrir
GitHub PoC2
Clone from gist
CVE-2023-29017CRITICAL07 abr 2023
vm2 Sandbox Escape vulnerability
60RIESGO
abrir
Exploit-DB
ABUS Security Camera TVIP 20000-21150 - LFI_ RCE and SSH Root Access
CVE-2023-26609HIGHremotehardware06 abr 2023
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - Broken Access Control
CVE-2023-0963HIGHwebappsphp06 abr 2023
SourceCodester Music Gallery Site POST Request Users.php access control
41RIESGO
abrir
GitHub PoC
qaisarafridi/cve-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware06 abr 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Exploit-DB
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-45701HIGHremotehardware06 abr 2023
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RIESGO
abrir
Exploit-DBVexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
CVE-2023-0943MEDIUMwebappsphp06 abr 2023
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-28432HIGHbajo ataque06 abr 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
Exploit-DBVexDay Proof
Intern Record System v1.0 - SQL Injection (Unauthenticated)
CVE-2022-40347CRITICALwebappsphp06 abr 2023
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType
48RIESGO
abrir
Exploit-DBVexDay Proof
Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
CVE-2022-40032CRITICALwebappsphp06 abr 2023
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque06 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
Exploit-DB
Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
CVE-2020-11798webappscgi06 abr 2023
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before
50RIESGO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project in PHP v 1.0 - SQL injection
CVE-2023-23156webappsphp06 abr 2023
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
23RIESGO
abrir
Exploit-DBVexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
CVE-2023-0902LOWwebappsphp06 abr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
CVE-2023-0961MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RIESGO
abrir
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
CVE-2023-0913MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System sql injection
33RIESGO
abrir
anteriorpágina 508 / 2581siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.