Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.953exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
24.460 exploits
Exploit-DB
RSA NetWitness Platform 12.2 - Incorrect Access Control / Code Execution
CVE-2022-47529localwindows08 abr 2023
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RIESGO
abrir
Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2022-43939HIGHbajo ataquewebappsjsp08 abr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RIESGO
abrir
Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2022-43769HIGHbajo ataquewebappsjsp08 abr 2023
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RIESGO
abrir
Exploit-DB
X2CRM v6.6/6.9 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2022-48178MEDIUMwebappsphp08 abr 2023
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via
33RIESGO
abrir
Exploit-DB
Goanywhere Encryption helper 7.1.1 - Remote Code Execution (RCE)
CVE-2023-0669HIGHbajo ataqueransomwarewebappsjava08 abr 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RIESGO
abrir
Exploit-DB
FortiRecorder 6.4.3 - Denial of Service
CVE-2022-41333MEDIUMdoshardware08 abr 2023
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RIESGO
abrir
Exploit-DB
ENTAB ERP 1.0 - Username PII leak
CVE-2022-30076MEDIUMwebappsasp08 abr 2023
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames
33RIESGO
abrir
Exploit-DB
Altenergy Power Control Software C1.2.5 - OS command injection
CVE-2023-28343webappshardware08 abr 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! v4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMbajo ataquewebappsphp08 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
Exploit-DB
Symantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)
CVE-2022-25630MEDIUMwebappsmultiple08 abr 2023
An authenticated user can embed malicious content with XSS into the admin group policy page.
33RIESGO
abrir
Exploit-DB
Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)
CVE-2022-0020MEDIUMwebappsmultiple08 abr 2023
Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface
33RIESGO
abrir
Exploit-DB
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
CVE-2022-47986CRITICALbajo ataqueransomwareremotemultiple07 abr 2023
IBM Aspera Faspex code execution
100RIESGO
abrir
Exploit-DB
ChurchCRM 4.5.1 - Authenticated SQL Injection
CVE-2023-24787webappsphp07 abr 2023
20RIESGO
abrir
Exploit-DB
Wondershare Dr Fone 12.9.6 - Privilege Escalation
CVE-2023-27010HIGHlocalwindows07 abr 2023
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all
41RIESGO
abrir
Exploit-DB
MAC 1200R - Directory Traversal
CVE-2021-27825HIGHwebappshardware07 abr 2023
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-stati
41RIESGO
abrir
Exploit-DB
Tenda N300 F3 12.01.01.48 - Malformed HTTP Request Header Processing
CVE-2020-35391CRITICALremotehardware07 abr 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RIESGO
abrir
Exploit-DB
NotrinosERP 0.7 - Authenticated Blind SQL Injection
CVE-2023-24788webappsphp07 abr 2023
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
23RIESGO
abrir
Exploit-DB
Docker based datastores for IBM Instana 241-2 243-0 - No Authentication
CVE-2023-27290CRITICALremotemultiple07 abr 2023
IBM Observability with Instana missing authentication
48RIESGO
abrir
Exploit-DB
Dompdf 1.2.1 - Remote Code Execution (RCE)
CVE-2022-28368webappsphp06 abr 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RIESGO
abrir
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - Broken Authentication
CVE-2023-0905HIGHwebappsphp06 abr 2023
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RIESGO
abrir
Exploit-DB
modoboa 2.0.4 - Admin TakeOver
CVE-2023-0777HIGHwebappspython06 abr 2023
Authentication Bypass by Primary Weakness in modoboa/modoboa
61RIESGO
abrir
Exploit-DB
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-45701HIGHremotehardware06 abr 2023
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RIESGO
abrir
Exploit-DB
TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE)
CVE-2023-22629HIGHremotewindows06 abr 2023
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page Master.php
CVE-2023-0962MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on music_list.php
CVE-2023-0938MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
CVE-2023-0961MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - Broken Access Control
CVE-2023-0963HIGHwebappsphp06 abr 2023
SourceCodester Music Gallery Site POST Request Users.php access control
41RIESGO
abrir
Exploit-DB
ABUS Security Camera TVIP 20000-21150 - LFI_ RCE and SSH Root Access
CVE-2023-26609HIGHremotehardware06 abr 2023
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RIESGO
abrir
Exploit-DBVexDay Proof
Intern Record System v1.0 - SQL Injection (Unauthenticated)
CVE-2022-40347CRITICALwebappsphp06 abr 2023
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType
48RIESGO
abrir
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection on manage_user.php
CVE-2023-0915MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System sql injection
33RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.