Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC12
imancybersecurity/CVE-2023-27350-POC
CVE-2023-27350CRITICALbajo ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC
Anonimo501/ssh_enum_users_CVE-2018-15473
CVE-2018-15473MEDIUM21 abr 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC10
veritas501/CVE-2023-0386
CVE-2023-0386HIGHbajo ataque20 abr 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC14
CVE-2023-21823 PoC
CVE-2023-21823HIGHbajo ataque20 abr 2023
Windows Graphics Component Remote Code Execution Vulnerability
71RIESGO
abrir
GitHub PoC
A little demonstration of cve-2021-41773 on httpd docker containers
CVE-2021-41773HIGHbajo ataqueransomware20 abr 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Dima2021/cve-2022-42889-text4shell
CVE-2022-4288918 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC4
randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE
CVE-2022-22963CRITICALbajo ataque17 abr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC4
Reproduce CVE-2023-2033
CVE-2023-2033HIGHbajo ataque17 abr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RIESGO
abrir
GitHub PoC1
msd0pe-1/CVE-2023-31714
CVE-2023-3171416 abr 2023
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
23RIESGO
abrir
GitHub PoC8
POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruption
CVE-2023-21716CRITICAL16 abr 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
💣💥💀 Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 abr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC18
CVE-2023-21839 Python版本
CVE-2023-21839HIGHbajo ataque15 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
GitHub PoC4
houqe/EXP_CVE-2018-19518
CVE-2018-1951815 abr 2023
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RIESGO
abrir
GitHub PoC3
CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)
CVE-2022-38181HIGHbajo ataque13 abr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RIESGO
abrir
GitHub PoC7
CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)
CVE-2022-38181HIGHbajo ataque13 abr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RIESGO
abrir
GitHub PoC
CHINA-china/MinIO_CVE-2023-28432_EXP
CVE-2023-28432HIGHbajo ataque13 abr 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC3
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
CVE-2022-46169CRITICALbajo ataque13 abr 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
hh-hunter/ml-CVE-2023-1177
CVE-2023-1177CRITICAL13 abr 2023
Path Traversal: '\..\filename' in mlflow/mlflow
75RIESGO
abrir
GitHub PoC1
F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800
CVE-2022-1388CRITICALbajo ataqueransomware12 abr 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC
nik0nz7/CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque11 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC
Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0
CVE-2022-46169CRITICALbajo ataque11 abr 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
FzBacon/CVE-2023-25234_Tenda_AC6_stack_overflow
CVE-2023-25234CRITICAL11 abr 2023
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInte
53RIESGO
abrir
GitHub PoC3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
CVE-2023-30256MEDIUM10 abr 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RIESGO
abrir
GitHub PoC1
Rust-based exploit for the CVE-2022-22963 vulnerability
CVE-2022-22963CRITICALbajo ataque10 abr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC33
Perform With Mass Exploiter In Joomla 4.2.8.
CVE-2023-23752MEDIUMbajo ataque09 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
CVE-2023-28432HIGHbajo ataque09 abr 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC
Ge-Per/Scanner-CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque08 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
ReachabilityOrg/cve-2022-42889-text4shell-docker
CVE-2022-4288908 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
jedai47/CVE-2018-7273
CVE-2018-727307 abr 2023
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RIESGO
abrir
GitHub PoC2
POC,EXP,chatGPT for me
CVE-2022-45047CRITICAL07 abr 2023
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RIESGO
abrir
anteriorpágina 275 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.