Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
77.449 exploits
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMbajo ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMbajo ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-37969HIGHbajo ataque09 mar 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC4
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHbajo ataqueransomware09 mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC7
Mass Auto Exploit CVE-2022-4395 Unauthenticated Arbitrary File Upload
CVE-2022-4395CRITICAL09 mar 2023
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
GitHub PoC135
Windows LPE exploit for CVE-2022-37969
CVE-2022-37969HIGHbajo ataque09 mar 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC4
Open Web Analytics 1.7.3 - Remote Code Execution
CVE-2022-2463709 mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
GitHub PoC2
Tenda f3 Malformed HTTP Request Header Processing Vulnerability.
CVE-2020-35391CRITICAL09 mar 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RIESGO
abrir
GitHub PoC4
SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.
CVE-2018-15473MEDIUM09 mar 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
sei-fish/CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware09 mar 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-47986CRITICALbajo ataqueransomware09 mar 2023
IBM Aspera Faspex code execution
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-35391CRITICAL09 mar 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-21224HIGHbajo ataque08 mar 2023
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a
83RIESGO
abrir
GitHub PoC
Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar
CVE-2023-21716CRITICAL08 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL08 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
local
CVE-2023-21716CRITICAL08 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC59
A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF document. The attacker could deliver this file as an email attachment (or other means).
CVE-2023-21716CRITICAL08 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC4
FeatherStark/CVE-2023-21716
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
adriyansyah-mf/CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque07 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALbajo ataque07 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-1604007 mar 2023
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMbajo ataque07 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
local
CVE-2023-21768HIGH07 mar 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RIESGO
abrir
GitHub PoC46
RTF Crash POC Python 3.11 Windows 10
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALbajo ataque07 mar 2023
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
GitHub PoC
Script in Ruby for the CVE-2022-35914 - RCE in GLPI
CVE-2022-35914CRITICALbajo ataque07 mar 2023
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
GitHub PoC8
spring cloud function 一键利用工具! by charis 博客https://charis3306.top/
CVE-2022-22963CRITICALbajo ataque07 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
Metasploit600
Pretalx Limited File Write to Remote Code Execution
CVE-2023-28458MEDIUM07 mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RIESGO
abrir
anteriorpágina 520 / 2582siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.