Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC1
MinIO Information Disclosure Vulnerability scanner by metasploit
CVE-2023-28432HIGHbajo ataque27 may 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC2
Exploit for Bad Binder
CVE-2019-2215HIGHbajo ataque27 may 2023
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC1
PoC for login with password hash in STARFACE
CVE-2023-33243HIGH26 may 2023
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RIESGO
abrir
GitHub PoC2
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp
CVE-2022-22947CRITICALbajo ataque26 may 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC7
Camaleon CMS v2.7.0 contain a Server-Side Template Injection (SSTI) vulnerability
CVE-2023-30145CRITICAL25 may 2023
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RIESGO
abrir
GitHub PoC6
MStore API <= 3.9.2 - Authentication Bypass
CVE-2023-2732CRITICAL25 may 2023
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
GitHub PoC
Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function
CVE-2022-22963CRITICALbajo ataque25 may 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC140
GitLab CVE-2023-2825 PoC. This PoC leverages a path traversal vulnerability to retrieve the /etc/passwd file from a system running GitLab 16.0.0.
CVE-2023-2825CRITICAL25 may 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
GitHub PoC
Vulnerable docker to test for: CVE-2023-32243
CVE-2023-32243CRITICAL24 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC
manavvedawala2/CVE-2023-32243-proof-of-concept
CVE-2023-32243CRITICAL23 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC
manavvedawala2/CVE-2023-32243-POC
CVE-2023-32243CRITICAL23 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC30
PoC for CVE-2023-28771 based on Rapid7's excellent writeup
CVE-2023-28771CRITICALbajo ataque23 may 2023
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir
GitHub PoC1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
CVE-2007-596222 may 2023
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RIESGO
abrir
GitHub PoC286
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL22 may 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RIESGO
abrir
GitHub PoC
This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).
CVE-2014-1812HIGHbajo ataqueransomware22 may 2023
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RIESGO
abrir
GitHub PoC
Dockerized POC for CVE-2022-42889 Text4Shell
CVE-2022-4288922 may 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
antisecc/CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque21 may 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
RCE Unauth in PyLoad <0.5.0b3.dev31
CVE-2023-0297CRITICAL21 may 2023
Code Injection in pyload/pyload
85RIESGO
abrir
GitHub PoC
antisecc/CVE-2022-24716
CVE-2022-24716HIGH20 may 2023
Path traversal in Icinga Web 2
78RIESGO
abrir
GitHub PoC1
Golang implementation of ThinVNC exploit CVE-2019-17662. For educational purposes only.
CVE-2019-1766219 may 2023
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir
GitHub PoC
xiaosed/CVE-2023-29919
CVE-2023-29919CRITICAL19 may 2023
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t
75RIESGO
abrir
GitHub PoC
Proof of Concept about a XSS Stored in SCM Manager 1.2 <= 1.60
CVE-2023-33829MEDIUM19 may 2023
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RIESGO
abrir
GitHub PoC59
CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/
CVE-2023-21554CRITICAL18 may 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RIESGO
abrir
GitHub PoC
Exploit to cve-2023-1671. So there is a test and exploitation function. The test sends a ping request to the dnslog domain from the vulnerable site. If the ping passes, the vulnerability exists, if it doesn't, then cve-2023-1671 is missing. The exploit function, on the other hand, sends a request with your command to the server.
CVE-2023-1671CRITICALbajo ataque17 may 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
GitHub PoC24
PoC for CVE-2023-20126
CVE-2023-20126CRITICAL17 may 2023
Cisco SPA112 2-Port Phone Adapters Remote Command Execution Vulnerability
60RIESGO
abrir
GitHub PoC2
CVE-2023-31702 is an authenticated SQL Injection vulnerability discovered in MicroWorld Technologies eScan Management Console version 14.0.1400.2281.
CVE-2023-31702HIGH17 may 2023
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
41RIESGO
abrir
GitHub PoC4
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Edit User functionality of the Microworld Technologies eScan Management Console (version 14.0.1400.2281).
CVE-2023-31703CRITICAL17 may 2023
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RIESGO
abrir
GitHub PoC51
Vulnerabilities Exploitation On Ubuntu 22.04
CVE-2023-0386HIGHbajo ataque16 may 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC11
POC for the CVE-2022-36944 vulnerability exploit
CVE-2022-36944CRITICAL16 may 2023
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There i
48RIESGO
abrir
GitHub PoC84
CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation
CVE-2023-32243CRITICAL15 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
anteriorpágina 271 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.