Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.528exploits catalogados
35.606CVEs con explotación pública
24.695probados en laboratorio
77.449 exploits
VulnCheck XDB
client-side
CVE-2021-30632HIGHbajo ataque21 mar 2023
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RIESGO
abrir
GitHub PoC
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
CVE-2022-36193CRITICAL21 mar 2023
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang
48RIESGO
abrir
GitHub PoC130
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.
CVE-2023-23397CRITICALbajo ataque20 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24716HIGH20 mar 2023
Path traversal in Icinga Web 2
78RIESGO
abrir
GitHub PoC1
Patch for MS Outlook Critical Vulnerability - CVSS 9.8
CVE-2023-23397CRITICALbajo ataque20 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit300
MinIO Bootstrap Verify Information Disclosure
CVE-2023-28432HIGHbajo ataque20 mar 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC1
Repo for CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque20 mar 2023
Unauthenticated Command Injection
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-23397CRITICALbajo ataque20 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-24716HIGH20 mar 2023
Path traversal in Icinga Web 2
78RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2022-24716HIGH20 mar 2023
Path traversal in Icinga Web 2
78RIESGO
abrir
GitHub PoC
this web is vulnerable against CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware20 mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque20 mar 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC1
Custom exploit written for enumerating usernames as per CVE-2016-6210
CVE-2016-6210MEDIUM19 mar 2023
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-24716HIGH19 mar 2023
Path traversal in Icinga Web 2
78RIESGO
abrir
VulnCheck XDB
local
CVE-2023-22809HIGH19 mar 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC2
ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook
CVE-2023-23397CRITICALbajo ataque19 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-23397CRITICALbajo ataque19 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-23397CRITICALbajo ataque18 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALbajo ataque18 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2509418 mar 2023
Tatsu < 3.3.12 - Unauthenticated RCE
60RIESGO
abrir
GitHub PoC73
POC for Veeam Backup and Replication CVE-2023-27532
CVE-2023-27532HIGHbajo ataqueransomware18 mar 2023
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RIESGO
abrir
Metasploit600
pfSense Restore RRD Data Command Injection
CVE-2023-2725318 mar 2023
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attac
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-27532HIGHbajo ataqueransomware18 mar 2023
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RIESGO
abrir
GitHub PoC1
This script exploits a vulnerability (CVE-2021-25094) in the TypeHub WordPress plugin.
CVE-2021-2509418 mar 2023
Tatsu < 3.3.12 - Unauthenticated RCE
60RIESGO
abrir
GitHub PoC1
CVE-2023-23397 C# PoC
CVE-2023-23397CRITICALbajo ataque18 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC24
CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vulnerability exists, and if it does, will give you a reverse shell.
CVE-2022-22963CRITICALbajo ataque18 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC9
djackreuter/CVE-2023-23397-PoC
CVE-2023-23397CRITICALbajo ataque18 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2021-31602MEDIUM18 mar 2023
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The
60RIESGO
abrir
GitHub PoC6
Exploit POC for CVE-2023-23397
CVE-2023-23397CRITICALbajo ataque17 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC7
Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.
CVE-2023-23397CRITICALbajo ataque17 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
anteriorpágina 517 / 2582siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.