Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.955exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
24.460 exploits
Exploit-DBVexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
CVE-2023-0916MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System Users.php access control
33RIESGO
abrir
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection on manage_user.php
CVE-2023-0915MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System sql injection
33RIESGO
abrir
Exploit-DB
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-45701HIGHremotehardware06 abr 2023
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RIESGO
abrir
Exploit-DB
Agilebio Lab Collector Electronic Lab Notebook v4.234 - Remote Code Execution (RCE)
CVE-2023-24217HIGHwebappsphp06 abr 2023
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
41RIESGO
abrir
Exploit-DB
TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE)
CVE-2023-22629HIGHremotewindows06 abr 2023
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - Broken Access Control
CVE-2023-0963HIGHwebappsphp06 abr 2023
SourceCodester Music Gallery Site POST Request Users.php access control
41RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page Master.php
CVE-2023-0962MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
CVE-2023-0961MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RIESGO
abrir
Exploit-DB
ABUS Security Camera TVIP 20000-21150 - LFI_ RCE and SSH Root Access
CVE-2023-26609HIGHremotehardware06 abr 2023
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RIESGO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on music_list.php
CVE-2023-0938MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RIESGO
abrir
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
CVE-2023-0913MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System sql injection
33RIESGO
abrir
Exploit-DB
modoboa 2.0.4 - Admin TakeOver
CVE-2023-0777HIGHwebappspython06 abr 2023
Authentication Bypass by Primary Weakness in modoboa/modoboa
61RIESGO
abrir
Exploit-DB
ImageMagick 7.1.0-49 - Arbitrary File Read
CVE-2022-44268MEDIUMlocalmultiple05 abr 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
Exploit-DB
CKEditor 5 35.4.0 - Cross-Site Scripting (XSS)
CVE-2022-48110MEDIUMwebappsphp05 abr 2023
CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CK
33RIESGO
abrir
Exploit-DB
Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure
CVE-2020-5330HIGHremotehardware05 abr 2023
Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22
46RIESGO
abrir
Exploit-DB
Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure
CVE-2019-15993HIGHremotehardware05 abr 2023
Cisco Small Business Switches Information Disclosure Vulnerability
46RIESGO
abrir
Exploit-DB
ImageMagick 7.1.0-49 - DoS
CVE-2022-44267MEDIUMdosphp05 abr 2023
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert proc
55RIESGO
abrir
Exploit-DBVexDay Proof
BTCPay Server v1.7.4 - HTML Injection
CVE-2023-0493MEDIUMwebappsmultiple05 abr 2023
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RIESGO
abrir
Exploit-DB
Calendar Event Multi View 1.4.07 - Unauthenticated Arbitrary Event Creation to Cross-Site Scripting (XSS)
CVE-2022-2846MEDIUMwebappsphp05 abr 2023
Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS
33RIESGO
abrir
Exploit-DB
Liferay Portal 6.2.5 - Insecure Permissions
CVE-2021-33990CRITICALwebappsjava05 abr 2023
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The
53RIESGO
abrir
Exploit-DB
Control Web Panel 7 (CWP7) v0.9.8.1147 - Remote Code Execution (RCE)
CVE-2022-44877CRITICALbajo ataquewebappsphp05 abr 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RIESGO
abrir
Exploit-DB
Froxlor 2.0.3 Stable - Remote Code Execution (RCE)
CVE-2023-0315HIGHwebappsphp05 abr 2023
Command Injection in froxlor/froxlor
78RIESGO
abrir
Exploit-DB
Binwalk v2.3.2 - Remote Command Execution (RCE)
CVE-2022-4510HIGHremotepython05 abr 2023
Path Traversal in binwalk
46RIESGO
abrir
Exploit-DB
itech TrainSmart r1044 - SQL injection
CVE-2021-36520HIGHwebappsphp05 abr 2023
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
41RIESGO
abrir
Exploit-DB
D-Link DIR-846 - Remote Command Execution (RCE) vulnerability
CVE-2022-46552HIGHremotehardware05 abr 2023
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan
46RIESGO
abrir
Exploit-DB
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
CVE-2023-0214MEDIUMwebappsmultiple05 abr 2023
XSS in Skyhigh Security SWG
33RIESGO
abrir
Exploit-DB
ERPNext 12.29 - Cross-Site Scripting (XSS)
CVE-2022-28598webappsjava05 abr 2023
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-contro
23RIESGO
abrir
Exploit-DBVexDay Proof
Answerdev 1.0.3 - Account Takeover
CVE-2023-0744CRITICALwebappsgo05 abr 2023
Improper Access Control in answerdev/answer
48RIESGO
abrir
Exploit-DB
Apache Tomcat 10.1 - Denial Of Service
CVE-2022-29885dosmultiple05 abr 2023
EncryptInterceptor does not provide complete protection on insecure networks
45RIESGO
abrir
Exploit-DBVexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
CVE-2022-46604HIGHwebappsphp05 abr 2023
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.