Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC84
CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation
CVE-2023-32243CRITICAL15 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC8
Abusing CVE-2023-28206 to make something useful
CVE-2023-28206HIGHbajo ataque15 may 2023
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5,
76RIESGO
abrir
GitHub PoC
school project
CVE-2019-15107CRITICALbajo ataqueransomware15 may 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC12
Follina (CVE-2022-30190) is a Microsoft Office zero-day vulnerability that has recently been discovered. It’s a high-severity vulnerability that hackers can leverage for remote code execution (RCE) attacks.
CVE-2022-30190HIGHbajo ataqueransomware14 may 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
Exploit for CVE-2023-32243 - Unauthorized Account Takeover.
CVE-2023-32243CRITICAL14 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC4
Akash7350/CVE-2021-22204
CVE-2021-22204MEDIUMbajo ataque14 may 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC6
Exploits for Tenda Ac8v4 stack-based overflow to Remote-Code Execution via Mipsel Ropping (CVE-2023-33669 - CVE-2023-33675)
CVE-2023-33669CRITICAL13 may 2023
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct
48RIESGO
abrir
GitHub PoC1
poc
CVE-2023-32243CRITICAL13 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC7
Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts
CVE-2021-3156HIGHbajo ataque13 may 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
raiden757/CVE-2020-17087
CVE-2020-17087HIGHbajo ataque13 may 2023
Windows Kernel Local Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC3
R0rt1z2/CVE-2022-38181
CVE-2022-38181HIGHbajo ataque12 may 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RIESGO
abrir
GitHub PoC
A simple PoC for CVE-2022-46169 a.k.a Cacti Unauthenticated Command Injection, a vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti prior from version 1.2.17 to 1.2.22
CVE-2022-46169CRITICALbajo ataque12 may 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC1
Exploit for grafana CVE-2021-43798
CVE-2021-43798HIGHbajo ataque12 may 2023
Grafana path traversal
100RIESGO
abrir
GitHub PoC
Baron SameEdit Heap Overflow LPE 1-Day Exploit
CVE-2021-3156HIGHbajo ataque11 may 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC4
redis未授权、redis_CVE-2022-0543检测利用二合一脚本
CVE-2022-0543CRITICALbajo ataque10 may 2023
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
GitHub PoC
Ejecución de exploit de deserialización con CVE-2017-5941
CVE-2017-594110 may 2023
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RIESGO
abrir
GitHub PoC
Ejecución de exploit de deserialización con CVE-2017-5941
CVE-2018-15133HIGHbajo ataque10 may 2023
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC
0xSalle/cve-2018-15133
CVE-2018-15133HIGHbajo ataque10 may 2023
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC
A exploit for CVE-2017-5638. This exploit works on versions 2.3.5-2.3.31 and 2.5 – 2.5.10
CVE-2017-5638CRITICALbajo ataqueransomware10 may 2023
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC1
Script of Network Security Project - Attack on CVE-2021-22555
CVE-2021-22555HIGHbajo ataque10 may 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
GitHub PoC3
A PoC exploit for CVE-2008-5862 - Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410
CVE-2008-586210 may 2023
Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitra
23RIESGO
abrir
GitHub PoC4
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252309 may 2023
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC4
CVE-2023-0386 EXP
CVE-2023-0386HIGHbajo ataque08 may 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC2
WordPress Plugin Gwolle Guestbook 1.5.3 - Remote File Inclusion
CVE-2015-835108 may 2023
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
GitHub PoC10
A PoC exploit for CVE-2019-15107 - Webmin Remote Code Execution
CVE-2019-15107CRITICALbajo ataqueransomware08 may 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC11
Apache Superset Auth Bypass (CVE-2023-27524)
CVE-2023-27524HIGHbajo ataque08 may 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC
An exploit script for CVE-2022-28368 designed to make exploitation less annoying, made for a HTB machine
CVE-2022-2836807 may 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RIESGO
abrir
GitHub PoC7
CVE-2023-23397 PoC
CVE-2023-23397CRITICALbajo ataque07 may 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC124
CVE-2023-0386 analysis and Exp
CVE-2023-0386HIGHbajo ataque06 may 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC9
A PoC exploit for CVE-2017-5487 - WordPress User Enumeration.
CVE-2017-548706 may 2023
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
anteriorpágina 272 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.