Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC22
CVE-2022-39227 : Proof of Concept
CVE-2022-39227CRITICAL07 jun 2023
Python-jwt subject to Authentication Bypass by Spoofing
48RIESGO
abrir
GitHub PoC1
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
CVE-2023-23488CRITICAL07 jun 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir
GitHub PoC
Spring rce environment for CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque07 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
Python 2.7
CVE-2023-2732CRITICAL06 jun 2023
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
GitHub PoC170
CVE-2023-25157 - GeoServer SQL Injection - PoC
CVE-2023-25157CRITICAL06 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir
GitHub PoC2
CVE-2023-34362-IOCs. More information on Deep Instinct's blog site.
CVE-2023-34362CRITICALbajo ataqueransomware06 jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
GitHub PoC
hqdat809/CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware05 jun 2023
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
MrDottt/CVE-2021-22911
CVE-2021-2291105 jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC
On May 23, 2023 GitLab released version 16.0.1 which fixed a critical vulnerability, CVE-2023-2825, affecting the Community Edition (CE) and Enterprise Edition (EE) version 16.0.0. The vulnerability allows unauthenticated users to read arbitrary files through a path traversal bug.
CVE-2023-2825CRITICAL05 jun 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
GitHub PoC
Proof of concept / CTF script for exploiting CVE-2022-46169 in Cacti, versions >=1.2.22
CVE-2022-46169CRITICALbajo ataque05 jun 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
CVE-2017-9248CRITICALbajo ataque05 jun 2023
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
GitHub PoC4
hoangprod/CVE-2021-31956-POC
CVE-2021-31956HIGHbajo ataque05 jun 2023
Windows NTFS Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC3
Poc&Exp,支持批量扫描,反弹shell
CVE-2022-22965CRITICALbajo ataque03 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
Exploit created in python3 to exploit known vulnerabilities in Apache web server (CVE-2021-41773, CVE-2021-42013)
CVE-2021-41773HIGHbajo ataqueransomware03 jun 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC3
CVE-2023-33246:Apache RocketMQ 远程命令执行漏洞检测工具
CVE-2023-33246CRITICALbajo ataque02 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC1
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
CVE-2022-044102 jun 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
GitHub PoC
[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure
CVE-2021-33690CRITICAL01 jun 2023
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RIESGO
abrir
GitHub PoC114
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALbajo ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC81
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALbajo ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC2
4mazing/CVE-2023-33246-Copy
CVE-2023-33246CRITICALbajo ataque31 may 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC1
Exploit for CVE:2010-2075. This exploit allows remote command execution in UnrealIRCd 3.2.8.1.
CVE-2010-207531 may 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
GitHub PoC2
A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability
CVE-2022-22965CRITICALbajo ataque31 may 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's password in plain text.
CVE-2023-33730CRITICAL30 may 2023
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2
48RIESGO
abrir
GitHub PoC
the proof of concept written in Python for an unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. This is a critical severity issue
CVE-2023-2825CRITICAL30 may 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
GitHub PoC62
I5N0rth/CVE-2023-33246
CVE-2023-33246CRITICALbajo ataque30 may 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC6
WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.
CVE-2020-0796CRITICALbajo ataqueransomware29 may 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
kw3h4/CVE-2023-21839-metasploit-scanner
CVE-2023-21839HIGHbajo ataque29 may 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
GitHub PoC2
Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...
CVE-2023-32243CRITICAL29 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC8
The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.
CVE-2019-905329 may 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC1
MinIO Information Disclosure Vulnerability scanner by metasploit
CVE-2023-28432HIGHbajo ataque27 may 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
anteriorpágina 270 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.