Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC
CVE-2020-14882 rewritten in PowerShell
CVE-2020-14882CRITICALbajo ataque28 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC
This repository contains a python script that will handle the majority of the dompdf cached font exploit (CVE-2022-28368), all you need to do is create the request
CVE-2022-2836828 abr 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RIESGO
abrir
GitHub PoC37
Cobalt Strike 4.4 猪猪版 去暗桩 去流量特征 beacon仿造真实API服务 修补CVE-2022-39197补丁
CVE-2022-39197MEDIUMbajo ataque28 abr 2023
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC3
Apache Superset Auth Bypass Vulnerability CVE-2023-27524.
CVE-2023-27524HIGHbajo ataque27 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC11
Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具
CVE-2023-27524HIGHbajo ataque27 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC6
A Python PoC of CVE-2022-21661, inspired from z92g's Go PoC
CVE-2022-21661HIGH27 abr 2023
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC
natceil/cve-2022-42475
CVE-2022-42475CRITICALbajo ataqueransomware27 abr 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
GitHub PoC
PrestaShop <1.7.8.9 Fix for CVE-2023-30839 and CVE-2023-30545
CVE-2023-30839CRITICAL27 abr 2023
PrestaShop vulnerable to SQL filter bypass leading to arbitrary write requests using "SQL Manager"
48RIESGO
abrir
GitHub PoC19
A collection of resources and information about CVE-2023-2033
CVE-2023-2033HIGHbajo ataque26 abr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RIESGO
abrir
GitHub PoC2
A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.
CVE-2022-0847HIGHbajo ataque26 abr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
Check for CVE-2014-0160
CVE-2014-0160HIGHbajo ataque25 abr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
UnrealIRCd 3.2.8.1 backdoor command execution exploit in Python 3 (CVE-2010-2075).
CVE-2010-207525 abr 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
GitHub PoC9
Exploit for Papercut CVE-2023-27350. [+] Reverse shell [+] Mass checking
CVE-2023-27350CRITICALbajo ataqueransomware25 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC25
CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5
CVE-2023-22621CRITICAL25 abr 2023
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RIESGO
abrir
GitHub PoC
2022 Spring Prof. 謝續平
CVE-2022-21907CRITICAL25 abr 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC112
Basic PoC for CVE-2023-27524: Insecure Default Configuration in Apache Superset
CVE-2023-27524HIGHbajo ataque25 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC1
Fix URL containing SPACES after Apache upgrade CVE-2023-25690
CVE-2023-25690CRITICAL25 abr 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RIESGO
abrir
GitHub PoC
ShyTangerine/cve-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware25 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC9
Perform With Mass Exploits In WSO Management.
CVE-2022-29464CRITICALbajo ataqueransomware25 abr 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC
andyhsu024/CVE-2021-29447
CVE-2021-29447HIGH24 abr 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC16
CVE-2023-1671-POC, based on dnslog platform
CVE-2023-1671CRITICALbajo ataque24 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
GitHub PoC13
CVE-2023-22894
CVE-2023-22894CRITICAL24 abr 2023
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RIESGO
abrir
GitHub PoC
msd0pe-1/CVE-2023-31747
CVE-2023-31747HIGH24 abr 2023
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RIESGO
abrir
GitHub PoC1
RubXkuB/PoC-Metabase-CVE-2021-41277
CVE-2021-41277CRITICALbajo ataque24 abr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
GitHub PoC3
Pre-Auth RCE in Sophos Web Appliance
CVE-2023-1671CRITICALbajo ataque23 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
GitHub PoC1
glen-pearson/ProxyLogon-CVE-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware23 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC55
Proof of Concept Exploit for PaperCut CVE-2023-27350
CVE-2023-27350CRITICALbajo ataqueransomware22 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC1
Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.
CVE-2022-1609CRITICAL22 abr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir
GitHub PoC5
A simple python script to check if a service is vulnerable
CVE-2023-27350CRITICALbajo ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC12
imancybersecurity/CVE-2023-27350-POC
CVE-2023-27350CRITICALbajo ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
anteriorpágina 274 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.