Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
77.401 exploits
Exploit-DB
CKEditor 5 35.4.0 - Cross-Site Scripting (XSS)
CVE-2022-48110MEDIUMwebappsphp05 abr 2023
CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CK
33RIESGO
abrir
Exploit-DB
Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure
CVE-2019-15993HIGHremotehardware05 abr 2023
Cisco Small Business Switches Information Disclosure Vulnerability
46RIESGO
abrir
Exploit-DB
D-Link DIR-846 - Remote Command Execution (RCE) vulnerability
CVE-2022-46552HIGHremotehardware05 abr 2023
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan
46RIESGO
abrir
Exploit-DBVexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
CVE-2022-46604HIGHwebappsphp05 abr 2023
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RIESGO
abrir
Exploit-DB
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
CVE-2023-0214MEDIUMwebappsmultiple05 abr 2023
XSS in Skyhigh Security SWG
33RIESGO
abrir
Exploit-DBVexDay Proof
BTCPay Server v1.7.4 - HTML Injection
CVE-2023-0493MEDIUMwebappsmultiple05 abr 2023
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RIESGO
abrir
Exploit-DB
ERPNext 12.29 - Cross-Site Scripting (XSS)
CVE-2022-28598webappsjava05 abr 2023
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-contro
23RIESGO
abrir
Exploit-DB
Provide Server v.14.4 XSS - CSRF & Remote Code Execution (RCE)
CVE-2023-23286MEDIUMwebappsmultiple05 abr 2023
Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the s
33RIESGO
abrir
Exploit-DB
Froxlor 2.0.3 Stable - Remote Code Execution (RCE)
CVE-2023-0315HIGHwebappsphp05 abr 2023
Command Injection in froxlor/froxlor
78RIESGO
abrir
Exploit-DB
Apache Tomcat 10.1 - Denial Of Service
CVE-2022-29885dosmultiple05 abr 2023
EncryptInterceptor does not provide complete protection on insecure networks
45RIESGO
abrir
Exploit-DB
ImageMagick 7.1.0-49 - DoS
CVE-2022-44267MEDIUMdosphp05 abr 2023
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert proc
55RIESGO
abrir
GitHub PoC7
Poc for CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque04 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMbajo ataque04 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
docker for CVE-2022-42889
CVE-2022-4288904 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC2
CVE-2014-6287
CVE-2014-6287CRITICALbajo ataque04 abr 2023
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALbajo ataque04 abr 2023
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288904 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-43769HIGHbajo ataque04 abr 2023
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-43939HIGHbajo ataque04 abr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RIESGO
abrir
Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
CVE-2022-43939HIGHbajo ataque04 abr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RIESGO
abrir
Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
CVE-2022-43769HIGHbajo ataque04 abr 2023
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RIESGO
abrir
GitHub PoC3
brosck/CVE-2006-3392
CVE-2006-339204 abr 2023
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
CVE-2023-23161webappsphp03 abr 2023
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RIESGO
abrir
Exploit-DB
SQL Monitor 12.1.31.893 - Cross-Site Scripting (XSS)
CVE-2022-47870MEDIUMwebappsmultiple03 abr 2023
A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows r
33RIESGO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
CVE-2023-23162webappsphp03 abr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
23RIESGO
abrir
Exploit-DB
GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusion
CVE-2022-31062MEDIUMwebappsphp03 abr 2023
Unauthenticated Local File Inclusion
33RIESGO
abrir
Exploit-DB
Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS)
CVE-2023-0084HIGHwebappsphp03 abr 2023
Metform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scripting
46RIESGO
abrir
Exploit-DB
GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration)
CVE-2022-31056CRITICALwebappsphp03 abr 2023
SQL injection with _actor parameter in GLPI
48RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque03 abr 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DB
GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)
CVE-2022-34128CRITICALwebappsphp03 abr 2023
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data
48RIESGO
abrir
anteriorpágina 510 / 2581siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.