Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
CVE-2023-0902LOWwebappsphp06 abr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RIESGO
abrir
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
CVE-2023-0904MEDIUMwebappsphp06 abr 2023
SourceCodester Employee Task Management System task-details.php sql injection
33RIESGO
abrir
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
CVE-2023-0902LOWwebappsphp06 abr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RIESGO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project in PHP v 1.0 - SQL injection
CVE-2023-23156webappsphp06 abr 2023
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
23RIESGO
abrir
Exploit-DBVexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
CVE-2023-0916MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System Users.php access control
33RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - Broken Access Control
CVE-2023-0963HIGHwebappsphp06 abr 2023
SourceCodester Music Gallery Site POST Request Users.php access control
41RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page Master.php
CVE-2023-0962MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
CVE-2023-0961MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RIESGO
abrir
Exploit-DBVexDay Proof
BTCPay Server v1.7.4 - HTML Injection
CVE-2023-0493MEDIUMwebappsmultiple05 abr 2023
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RIESGO
abrir
Exploit-DBVexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
CVE-2022-46604HIGHwebappsphp05 abr 2023
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RIESGO
abrir
Exploit-DBVexDay Proof
Answerdev 1.0.3 - Account Takeover
CVE-2023-0744CRITICALwebappsgo05 abr 2023
Improper Access Control in answerdev/answer
48RIESGO
abrir
Exploit-DBVexDay Proof
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
CVE-2020-25213CRITICALbajo ataquewebappsphp03 abr 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
CVE-2023-23161webappsphp03 abr 2023
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RIESGO
abrir
Exploit-DBVexDay Proof
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
CVE-2023-23488CRITICALwebappsphp03 abr 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)
CVE-2022-31126CRITICALwebappspython03 abr 2023
Unauthenticated Remote Code Execution in Roxy-wi
75RIESGO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
CVE-2023-23163webappsphp03 abr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parame
23RIESGO
abrir
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Improper Authentication Control
CVE-2022-31125CRITICALwebappspython03 abr 2023
Authentication Bypass in Roxy-wi
53RIESGO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
CVE-2023-23162webappsphp03 abr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
23RIESGO
abrir
Exploit-DBVexDay Proof
GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-2884CRITICALwebappsruby01 abr 2023
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3
70RIESGO
abrir
Exploit-DBVexDay Proof
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
CVE-2022-48197webappsphp01 abr 2023
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RIESGO
abrir
Exploit-DBVexDay Proof
Apache 2.4.x - Buffer Overflow
CVE-2021-44790webappsmultiple01 abr 2023
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RIESGO
abrir
Exploit-DBVexDay Proof
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-1565HIGHwebappsphp29 mar 2023
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RIESGO
abrir
Exploit-DBVexDay Proof
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
CVE-2022-3552HIGHwebappsphp28 mar 2023
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RIESGO
abrir
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39290HIGHwebappsphp27 mar 2023
CSRF key bypass using HTTP methods in zoneminder
41RIESGO
abrir
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39285HIGHwebappsphp27 mar 2023
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RIESGO
abrir
Exploit-DBVexDay Proof
Grafana <=6.2.4 - HTML Injection
CVE-2019-13068webappstypescript27 mar 2023
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RIESGO
abrir
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39291MEDIUMwebappsphp27 mar 2023
Denial of service through logs in zoneminder
33RIESGO
abrir
Exploit-DBVexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
CVE-2022-3142webappsphp25 mar 2023
NEX-Forms < 7.9.7 - Authenticated SQLi
43RIESGO
abrir
Exploit-DBVexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
CVE-2022-26149webappsphp25 mar 2023
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RIESGO
abrir
Exploit-DBVexDay Proof
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
CVE-2022-26982webappsphp25 mar 2023
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.