Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
77.449 exploits
GitHub PoC9
Exploit to CVE-2022-46169 vulnerability
CVE-2022-46169CRITICALbajo ataque13 ene 2023
Unauthenticated Command Injection
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-21661HIGH13 ene 2023
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC1
CVE 2022-45299
CVE-2022-45299CRITICAL13 ene 2023
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi
48RIESGO
abrir
Metasploit300
Wordpress Paid Membership Pro code Unauthenticated SQLi
CVE-2023-23488CRITICAL12 ene 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir
GitHub PoC2
cve-2010-1622 Learning Environment
CVE-2010-162211 ene 2023
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-48323CRITICAL10 ene 2023
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A
75RIESGO
abrir
GitHub PoC326
Wh04m1001/CVE-2023-21752
CVE-2023-21752HIGH10 ene 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RIESGO
abrir
Metasploit600
ManageEngine Endpoint Central Unauthenticated SAML RCE
CVE-2022-47966CRITICALbajo ataqueransomware10 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
Metasploit600
Ancillary Function Driver (AFD) for WinSock Elevation of Privilege
CVE-2023-21768HIGH10 ene 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RIESGO
abrir
Metasploit600
ManageEngine ADSelfService Plus Unauthenticated SAML RCE
CVE-2022-47966CRITICALbajo ataqueransomware10 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
Metasploit600
ManageEngine ServiceDesk Plus Unauthenticated SAML RCE
CVE-2022-47966CRITICALbajo ataqueransomware10 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
GitHub PoC
CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8
CVE-2021-29447HIGH10 ene 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC
CVE-2017-16995 Linux POC
CVE-2017-1699509 ene 2023
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC
G01d3nW01f/CVE-2021-43798
CVE-2021-43798HIGHbajo ataque09 ene 2023
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-23131CRITICALbajo ataque09 ene 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC28
CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad
CVE-2023-0297CRITICAL09 ene 2023
Code Injection in pyload/pyload
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL09 ene 2023
Code Injection in pyload/pyload
85RIESGO
abrir
GitHub PoC
zabbix saml bypass
CVE-2022-23131CRITICALbajo ataque09 ene 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-999509 ene 2023
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC1
.NET console application that exploits CVE-2018-9995 vulnerability
CVE-2018-999509 ene 2023
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC
CVE-2017-7308 POC
CVE-2017-730809 ene 2023
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RIESGO
abrir
GitHub PoC
Sophos EXploit
CVE-2022-1040CRITICALbajo ataque08 ene 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1040CRITICALbajo ataque08 ene 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RIESGO
abrir
GitHub PoC26
Dell Driver EoP (CVE-2021-21551)
CVE-2021-21551HIGHbajo ataque07 ene 2023
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC2
CVE-2018-19321
CVE-2018-19321HIGHbajo ataqueransomware07 ene 2023
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X
71RIESGO
abrir
GitHub PoC1
wr0x00/cve-2022-23131
CVE-2022-23131CRITICALbajo ataque07 ene 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-23131CRITICALbajo ataque07 ene 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHbajo ataque07 ene 2023
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC11
Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.
CVE-2022-39073CRITICAL07 ene 2023
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an att
48RIESGO
abrir
GitHub PoC37
CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224
CVE-2021-38003HIGHbajo ataque07 ene 2023
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo
83RIESGO
abrir
anteriorpágina 530 / 2582siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.