Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC2
Tools for working with ImageMagick to handle arbitrary file read vulnerabilities. Generate, read, and apply profile information to PNG files using a command-line interface.
CVE-2022-44268MEDIUM25 jun 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC
pashayogi/CVE-2023-22809
CVE-2023-22809HIGH25 jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC1
Based on the x.pl exploit/loader script for CVE-2009-1151
CVE-2009-1151CRITICALbajo ataque24 jun 2023
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RIESGO
abrir
GitHub PoC1
Windows Network File System Remote exploit (DoS) PoC
CVE-2022-30136CRITICAL23 jun 2023
Windows Network File System Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
puckiestyle/cve-2023-27997
CVE-2023-27997CRITICALbajo ataqueransomware23 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC10
An exploit for CVE-2018-5955 GitStack 2.3.10 Unauthenticated RCE
CVE-2018-595523 jun 2023
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir
GitHub PoC1
imbas007/CVE-2023-27997-Check
CVE-2023-27997CRITICALbajo ataqueransomware22 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC34
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
CVE-2022-42475CRITICALbajo ataqueransomware21 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
GitHub PoC
sonpt-afk/CVE-2018-11776-FIS
CVE-2018-11776HIGHbajo ataque21 jun 2023
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC2
Analysis & Exploit
CVE-2023-22809HIGH20 jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC1
Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info
CVE-2021-42013CRITICALbajo ataqueransomware20 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC11
cfielding-r7/poc-cve-2023-2868
CVE-2023-2868CRITICALbajo ataque20 jun 2023
Remote Code injection in Barracuda Email Security Gateway
100RIESGO
abrir
GitHub PoC2
PoC and exploit for CVE-2022-22965 Spring4Shell
CVE-2022-22965CRITICALbajo ataque20 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC19
Exploits for a heap overflow in MiniDLNA <=1.3.2 (CVE-2023-33476)
CVE-2023-33476CRITICAL20 jun 2023
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by
48RIESGO
abrir
GitHub PoC2
POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability
CVE-2022-0847HIGHbajo ataque20 jun 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
overgrowncarrot1/CVE-2021-22911
CVE-2021-2291119 jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC69
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
CVE-2023-27372CRITICAL19 jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC57
Openfire Console Authentication Bypass Vulnerability with RCE plugin
CVE-2023-32315HIGHbajo ataque18 jun 2023
Openfire administration console authentication bypass
100RIESGO
abrir
GitHub PoC7
CVE-2023-24078 for FuguHub / BarracudaDrive
CVE-2023-24078HIGH17 jun 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RIESGO
abrir
GitHub PoC1
CVE-2023-24078 for FuguHub / BarracudaDrive
CVE-2023-24078HIGH17 jun 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RIESGO
abrir
GitHub PoC23
FortiOS 管理界面中的堆内存下溢导致远程代码执行
CVE-2023-25610CRITICAL17 jun 2023
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0
53RIESGO
abrir
GitHub PoC134
Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
CVE-2023-27997CRITICALbajo ataqueransomware16 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC6
Repository with everything I have tracking the impact of MOVEit CVE-2023-34362
CVE-2023-34362CRITICALbajo ataqueransomware16 jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
GitHub PoC27
POC FortiOS SSL-VPN buffer overflow vulnerability
CVE-2023-27997CRITICALbajo ataqueransomware16 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC4
Joomla未授权访问漏洞
CVE-2023-23752MEDIUMbajo ataque16 jun 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC15
SolarView Compact through 6.00 downloader.php commands injection (RCE) nuclei-templates
CVE-2023-23333CRITICAL16 jun 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
GitHub PoC
CVE-2023-34600
CVE-2023-34600CRITICAL16 jun 2023
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
53RIESGO
abrir
GitHub PoC
Exploit for CVE-2022-44136 for chcking security of your site
CVE-2022-44136CRITICAL15 jun 2023
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RIESGO
abrir
GitHub PoC1
overgrowncarrot1/CVE-2023-0297
CVE-2023-0297CRITICAL15 jun 2023
Code Injection in pyload/pyload
85RIESGO
abrir
GitHub PoC
Samba 3.0.20
CVE-2007-244715 jun 2023
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
anteriorpágina 268 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.