Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
13.689 exploits
GitHub PoC2
Nmap NSE script to dump / test Solarwinds CVE-2023-23333 vulnerability
CVE-2023-23333CRITICAL01 ago 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
GitHub PoC
CVE-2022-1388 - F5 Router RCE Replica
CVE-2022-1388CRITICALbajo ataqueransomware01 ago 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC3
Perform With Mass Remote Code Execution In SPIP Version (4.2.1)
CVE-2023-27372CRITICAL31 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC5
Tools to scanner & exploit cve-2023-35078
CVE-2023-35078CRITICALbajo ataqueransomware31 jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
GitHub PoC
Easy and non-intrusive script to check for CVE-2023-35078
CVE-2023-35078CRITICALbajo ataqueransomware31 jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
GitHub PoC
timsonner/cve-2014-0160-heartbleed
CVE-2014-0160HIGHbajo ataque31 jul 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
GeoServer OGC Filter SQL Injection Vulnerabilities
CVE-2023-25157CRITICAL31 jul 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir
GitHub PoC
Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)
CVE-2022-26134CRITICALbajo ataqueransomware30 jul 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
#comeonits2023 #ie9 #Storm-0978
CVE-2023-36884HIGHbajo ataqueransomware30 jul 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC
cashapp323232/CVE-2023-2868CVE-2023-2868
CVE-2023-2868CRITICALbajo ataque30 jul 2023
Remote Code injection in Barracuda Email Security Gateway
100RIESGO
abrir
GitHub PoC117
CVE-2023-35078 Remote Unauthenticated API Access Vulnerability Exploit POC
CVE-2023-35078CRITICALbajo ataqueransomware29 jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
GitHub PoC5
Proof of concept script to check if the site is vulnerable to CVE-2023-35078
CVE-2023-35078CRITICALbajo ataqueransomware29 jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
GitHub PoC9
CVE-2023-22884 PoC
CVE-2023-22884CRITICAL29 jul 2023
Apache Airflow, Apache Airflow MySQL Provider: Arbitrary file read via MySQL provider in Apache Airflow
53RIESGO
abrir
GitHub PoC
Pseudo shell for CVE-2013-0156.
CVE-2013-015629 jul 2023
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir
GitHub PoC
JohnGilbert57/CVE-2021-4034-Capture-the-flag
CVE-2021-4034HIGHbajo ataque28 jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC17
Voyag3r-Security/CVE-2023-1389
CVE-2023-1389HIGHbajo ataque28 jul 2023
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RIESGO
abrir
GitHub PoC2
ridsoliveira/Fix-CVE-2023-36884
CVE-2023-36884HIGHbajo ataqueransomware28 jul 2023
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC1
Exploit for the vulnerability of Ultimate Member Plugin.
CVE-2023-346027 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
GitHub PoC2
CVE-2021-3129 | Laravel Debug Mode Vulnerability
CVE-2021-3129CRITICALbajo ataqueransomware27 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
Laravel RCE (CVE-2021-3129)
CVE-2021-3129CRITICALbajo ataqueransomware26 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
simple program for joomla scanner CVE-2023-23752 with target list
CVE-2023-23752MEDIUMbajo ataque26 jul 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE
CVE-2021-22204MEDIUMbajo ataque25 jul 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC2
Python script to exploit PlaySMS before 1.4.3
CVE-2020-8644CRITICALbajo ataque25 jul 2023
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RIESGO
abrir
GitHub PoC1
CVE-2022-23305 Log4J JDBCAppender SQl injection POC
CVE-2022-23305CRITICAL24 jul 2023
SQL injection in JDBC Appender in Apache Log4j V1
60RIESGO
abrir
GitHub PoC1
Learn what is BlueJam CVE-2017-0781
CVE-2017-078124 jul 2023
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
GitHub PoC46
A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.
CVE-2017-7921CRITICALbajo ataque24 jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC1
ImageMagick Arbitrary Read Files - CVE-2022-44268
CVE-2022-44268MEDIUM23 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC228
RCE exploit for CVE-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir
GitHub PoC11
CVE-2023-3519 vuln for nuclei scanner
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir
GitHub PoC1
NetScaler (Citrix ADC) CVE-2023-3519 Scanner
CVE-2023-3519CRITICALbajo ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir
anteriorpágina 263 / 457siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.