Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.745exploits catalogados
38.712CVEs con explotación pública
24.695probados en laboratorio
82.745 exploits
GitHub PoC★ 1
CVE-2023-33592批量漏洞利用程序
CVE-2023-33592—14 jul 2023
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RIESGO
abrir ↗
GitHub PoC★ 22
Muhammad-Ali007/OutlookNTLM_CVE-2023-23397
CVE-2023-23397CRITICALbajo ataque14 jul 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 46
Apache RocketMQ Arbitrary File Write Vulnerability Exploit
CVE-2023-37582CRITICAL14 jul 2023
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-37582CRITICAL14 jul 2023
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2023-23397CRITICALbajo ataque14 jul 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 1
Recent Campaign abusing CVE-2023-36884
CVE-2023-36884HIGHbajo ataqueransomware13 jul 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALbajo ataqueransomware13 jul 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir ↗
GitHub PoC★ 2
This is a Python3 script that demonstrates an exploit for a Blind SQL Injection vulnerability in WebERP version 4.15.
CVE-2019-13292—13 jul 2023
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is d
23RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-4262HIGHbajo ataque13 jul 2023
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corru
76RIESGO
abrir ↗
GitHub PoC★ 106
Full Chain Analysis of CVE-2022-4262, a non-trivial feedback slot type confusion in V8.
CVE-2022-4262HIGHbajo ataque13 jul 2023
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corru
76RIESGO
abrir ↗
Metasploit600
BoidCMS Command Injection
CVE-2023-38836—13 jul 2023
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header t
60RIESGO
abrir ↗
GitHub PoC
Proof of concept for LabVIEW Web Server HTTP Get Newline DoS vulnerability
CVE-2002-0748—13 jul 2023
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET reques
28RIESGO
abrir ↗
Metasploit600
Sonicwall
CVE-2023-34127HIGH12 jul 2023
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GM
58RIESGO
abrir ↗
Metasploit600
Sonicwall
CVE-2023-34133HIGH12 jul 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and
58RIESGO
abrir ↗
Metasploit600
Sonicwall
CVE-2023-34124CRITICAL12 jul 2023
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
75RIESGO
abrir ↗
Metasploit600
Sonicwall
CVE-2023-34132—12 jul 2023
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the
18RIESGO
abrir ↗
GitHub PoC
F5-BIG-IP Remote Code Execution Vulnerability CVE-2022-1388: A Case Study
CVE-2022-1388CRITICALbajo ataqueransomware12 jul 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗
GitHub PoC★ 26
The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection script checks if they exist. Provided AS-IS without any warrenty.
CVE-2023-36884HIGHbajo ataqueransomware12 jul 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-24489CRITICALbajo ataque12 jul 2023
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RIESGO
abrir ↗
GitHub PoC★ 13
This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server. The script supports both Windows and Linux (On testing) platforms, and it can be used to exploit individual targets or perform mass checking on a list of URLs.
CVE-2023-24489CRITICALbajo ataque12 jul 2023
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-28121—12 jul 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-28121—12 jul 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RIESGO
abrir ↗
Exploit-DB
Game Jackal Server v5 - Unquoted Service Path _GJServiceV5_
CVE-2023-36166—localwindows11 jul 2023
20RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-1732HIGHbajo ataqueransomware11 jul 2023
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 1
Python script that generates pfs payloads to exploit CVE-2022-4510
CVE-2022-4510HIGH11 jul 2023
Path Traversal in binwalk
46RIESGO
abrir ↗
Metasploit600
Microsoft Error Reporting Local Privilege Elevation Vulnerability
CVE-2023-36874HIGHbajo ataque11 jul 2023
Windows Error Reporting Service Elevation of Privilege Vulnerability
98RIESGO
abrir ↗
Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTAgentService_
CVE-2023-36164—localwindows11 jul 2023
20RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM11 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-27372CRITICAL11 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗
GitHub PoC★ 1
asepsaepdin/CVE-2021-1732
CVE-2021-1732HIGHbajo ataqueransomware11 jul 2023
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir ↗
← anteriorpágina 564 / 2759siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.