Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
77.449 exploits
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware27 ene 2023
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC2
In Paradox Security System IPR512 web panel, an unauthenticated user can input JavaScript string, such as </script> that will overwrite configurations in the file "login.xml" and cause the login form to crash and make it unavailable.
CVE-2023-24709HIGH26 ene 2023
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RIESGO
abrir
GitHub PoC1
Relativ3Pa1n/CVE-2014-2383-LFI-to-RCE-Escalation
CVE-2014-238326 ene 2023
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-238326 ene 2023
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RIESGO
abrir
GitHub PoC
vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 2.39 and older. Git for Windows was also patched to address an additional, Windows-specific issue known as CVE-2022-41953.
CVE-2022-41903CRITICAL26 ene 2023
Integer overflow in `git archive`, `git log --format` leading to RCE in git
60RIESGO
abrir
VulnCheck XDB
local
CVE-2023-2405525 ene 2023
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,
23RIESGO
abrir
GitHub PoC2
DDoS Tool which exploits vulnerability CVE-2004-2449 from vendor GameSpy (now known as OpenSpy). User is prompted for input IP address, and port. (NOTE: Please use this responsibly, I made this as a proof of concept of vulnerability exploitation ONLY. I do not endorse DOSing, DDoSing, or cheating in any way. Use this at your own risk.)
CVE-2004-244925 ene 2023
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial
23RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware24 ene 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-2405524 ene 2023
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,
23RIESGO
abrir
GitHub PoC2
Drity Pipe Linux Kernel 1-Day Exploit
CVE-2022-0847HIGHbajo ataque24 ene 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC6
A proof of concept exploit for a wordpress 5.6 media library vulnerability
CVE-2021-29447HIGH24 ene 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC1
A pwnkit N-Day exploit
CVE-2021-4034HIGHbajo ataqueransomware24 ene 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque24 ene 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
CVE-2022-31704CRITICAL24 ene 2023
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
85RIESGO
abrir
Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
CVE-2022-31711MEDIUM24 ene 2023
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sen
53RIESGO
abrir
Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
CVE-2022-31706CRITICAL24 ene 2023
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi
85RIESGO
abrir
GitHub PoC
it is the official Fix of Wordpress CVE-2018-6389.
CVE-2018-638923 ene 2023
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC7
The manage engine mass loader for CVE-2022-47966
CVE-2022-47966CRITICALbajo ataqueransomware23 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-46689HIGH23 ene 2023
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RIESGO
abrir
GitHub PoC28
Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.
CVE-2022-47966CRITICALbajo ataqueransomware23 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-36804HIGHbajo ataque23 ene 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC2
Run on your ManageEngine server
CVE-2022-47966CRITICALbajo ataqueransomware23 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-47966CRITICALbajo ataqueransomware23 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-47966CRITICALbajo ataqueransomware23 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
GitHub PoC8
A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects all versions of Bitbucket Server and Data Center released before versions <7.6.17, <7.17.10, <7.21.4, <8.0.3, <8.1.2, <8.2.2, and <8.3.1
CVE-2022-36804HIGHbajo ataque23 ene 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALbajo ataque22 ene 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
GitHub PoC6
Python exploit for RCE in Wordpress
CVE-2020-25213CRITICALbajo ataque22 ene 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
GitHub PoC1
Demo webapp vulnerable to CVE-2022-44900
CVE-2022-44900CRITICAL21 ene 2023
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea
48RIESGO
abrir
GitHub PoC165
A script to automate privilege escalation with CVE-2023-22809 vulnerability
CVE-2023-22809HIGH21 ene 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC4
Remote Code Execution in Social Warfare Plugin before 3.5.3 for Wordpress.
CVE-2019-9978MEDIUMbajo ataque20 ene 2023
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
anteriorpágina 528 / 2582siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.