Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC124
CVE-2023-0386 analysis and Exp
CVE-2023-0386HIGHbajo ataque06 may 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC
User enumeration for CVE-2018-15473
CVE-2018-15473MEDIUM05 may 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC420
CVE-2023-0386在ubuntu22.04上的提权
CVE-2023-0386HIGHbajo ataque05 may 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC1
mclbn/docker-cve-2018-15473
CVE-2018-15473MEDIUM05 may 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC2
simple Python exploit using CVE-2018-7449 on embOS/IP FTP Server v3.22
CVE-2018-744905 may 2023
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in
23RIESGO
abrir
GitHub PoC
c7w1n/CVE-2023-30185
CVE-2023-30185CRITICAL05 may 2023
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\System
48RIESGO
abrir
GitHub PoC4
Satheesh575555/linux-4.19.72_CVE-2023-0386
CVE-2023-0386HIGHbajo ataque04 may 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC
🐍 Python Exploit for CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque04 may 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
This is a exploit of CVE-2019-16278 for Nostromo 1.9.6 RCE. This exploit allows RCE on the victim machine.
CVE-2019-16278CRITICALbajo ataque04 may 2023
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC3
Perform With Apache-SuperSet Leaked Token [CSRF]
CVE-2023-27524HIGHbajo ataque04 may 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC
threatcode/CVE-2008-6806
CVE-2008-680604 may 2023
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RIESGO
abrir
GitHub PoC
A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.
CVE-2023-27524HIGHbajo ataque04 may 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC6
0xhav0c/CVE-2013-5211
CVE-2013-521103 may 2023
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
GitHub PoC
Binaries for CVE-2022-22963
CVE-2022-22963CRITICALbajo ataque03 may 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC1
An exploitation of CVE-2022-30190 (Follina)
CVE-2022-30190HIGHbajo ataqueransomware02 may 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Este es un código del exploit CVE-2022-46169, que recree utilizando Python3! Si por ahí estás haciendo una máquina de HTB, esto te puede ser útil... 🤞✨
CVE-2022-46169CRITICALbajo ataque02 may 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC1
Improved PoC for Unauthenticated RCE on Cacti <= 1.2.22 - CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque02 may 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
tuankiethkt020/Phat-hien-CVE-2017-8464
CVE-2017-8464HIGHbajo ataque01 may 2023
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC
Zoo1sondv/CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware01 may 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC3
Exploit for cacti version 1.2.22
CVE-2022-46169CRITICALbajo ataque01 may 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC42
This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.
CVE-2022-46169CRITICALbajo ataque01 may 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
check cve-2022-0847
CVE-2022-0847HIGHbajo ataque30 abr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque30 abr 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
Cisco r042 research
CVE-2023-20025CRITICAL30 abr 2023
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co
48RIESGO
abrir
GitHub PoC
gretchenfrage/CVE-2023-2033-analysis
CVE-2023-2033HIGHbajo ataque30 abr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RIESGO
abrir
GitHub PoC
MrE-Fog/CVE-2014-0160-Chrome-Plugin
CVE-2014-0160HIGHbajo ataque30 abr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
zPrototype/CVE-2023-29809
CVE-2023-29809CRITICAL30 abr 2023
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RIESGO
abrir
GitHub PoC2
Akash7350/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware30 abr 2023
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
zPrototype/CVE-2023-29983
CVE-2023-29983MEDIUM29 abr 2023
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary co
33RIESGO
abrir
GitHub PoC
PoC for CVE-2022-46169 that affects Cacti 1.2.22 version
CVE-2022-46169CRITICALbajo ataque29 abr 2023
Unauthenticated Command Injection
100RIESGO
abrir
anteriorpágina 273 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.