Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.745exploits catalogados
38.712CVEs con explotación pública
24.695probados en laboratorio
82.745 exploits
VulnCheck XDB
local
CVE-2021-1732HIGHbajo ataqueransomware11 jul 2023
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 2
CVE-2023-27372-SPIP-CMS-Bypass
CVE-2023-27372CRITICAL11 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-3460—11 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-27372CRITICAL11 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-45354MEDIUM11 jul 2023
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RIESGO
abrir ↗
Exploit-DB
Game Jackal Server v5 - Unquoted Service Path _GJServiceV5_
CVE-2023-36166—localwindows11 jul 2023
20RIESGO
abrir ↗
GitHub PoC
CVE-2023-3460
CVE-2023-3460—11 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir ↗
GitHub PoC★ 7
Exploit and scanner for CVE-2023-3460
CVE-2023-3460—11 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir ↗
Exploit-DB
AVG Anti Spyware 7.5 - Unquoted Service Path _AVG Anti-Spyware Guard_
CVE-2023-36167—localwindows11 jul 2023
20RIESGO
abrir ↗
Exploit-DB
BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
CVE-2023-36163—webappsphp11 jul 2023
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RIESGO
abrir ↗
GitHub PoC
asepsaepdin/CVE-2021-3560
CVE-2021-3560HIGHbajo ataque10 jul 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-22809HIGH10 jul 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗
GitHub PoC
asepsaepdin/CVE-2021-4034
CVE-2021-4034HIGHbajo ataqueransomware10 jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
GitHub PoC★ 6
asepsaepdin/CVE-2023-22809
CVE-2023-22809HIGH10 jul 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware10 jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque10 jul 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗
GitHub PoC★ 1
Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.
CVE-2022-0847HIGHbajo ataque09 jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗
GitHub PoC
bthnrml/guncel-cve-2019-9053.py
CVE-2019-9053—09 jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-35843HIGH09 jul 2023
NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access
56RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-3460—09 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2023-34960—09 jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque09 jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-34362CRITICALbajo ataqueransomware09 jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗
GitHub PoC
Mass CVE-2023-3460.
CVE-2023-3460—09 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir ↗
GitHub PoC★ 4
A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder.
CVE-2023-32235HIGH09 jul 2023
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RIESGO
abrir ↗
GitHub PoC★ 10
POC for CVE-2023-34362 affecting MOVEit Transfer
CVE-2023-34362CRITICALbajo ataqueransomware09 jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗
GitHub PoC
Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH08 jul 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RIESGO
abrir ↗
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code via the MTAgentService component
CVE-2023-36164—08 jul 2023
20RIESGO
abrir ↗
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code and gain privileges via the SchedulerService.exe component.
CVE-2023-36165—08 jul 2023
20RIESGO
abrir ↗
GitHub PoC★ 2
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL
CVE-2023-36163—08 jul 2023
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RIESGO
abrir ↗
← anteriorpágina 565 / 2759siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.