Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC
jacquesquail/CVE-2023-23397
CVE-2023-23397CRITICALbajo ataque29 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
0759104103/cd-CVE-2019-11932
CVE-2019-1193229 mar 2023
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC
cyberdesu/Remote-Buffer-overflow-CVE-2003-0172
CVE-2003-017228 mar 2023
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote at
28RIESGO
abrir
GitHub PoC
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
CVE-2022-44877CRITICALbajo ataque27 mar 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RIESGO
abrir
GitHub PoC
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
CVE-2022-39952CRITICAL27 mar 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RIESGO
abrir
GitHub PoC319
EXP for CVE-2023-28434 MinIO unauthorized to RCE
CVE-2023-28434HIGHbajo ataque27 mar 2023
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RIESGO
abrir
GitHub PoC3
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24716HIGH27 mar 2023
Path traversal in Icinga Web 2
78RIESGO
abrir
GitHub PoC2
通过vulhub的复现过程实现了,基本的批量检测。比较垃圾但是勉强能用
CVE-2023-28432HIGHbajo ataque27 mar 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
CVE-2019-1653HIGHbajo ataque26 mar 2023
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
GitHub PoC5
0xNahim/CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque26 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC1
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
GitHub PoC3
Unauthenticated RCE in Open Web Analytics version <1.7.4
CVE-2022-2463726 mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
GitHub PoC3
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
GitHub PoC
pumpkinpiteam/CVE-2022-24716
CVE-2022-24716HIGH26 mar 2023
Path traversal in Icinga Web 2
78RIESGO
abrir
GitHub PoC
Brandaoo/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)
CVE-2019-0708CRITICALbajo ataqueransomware25 mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC4
Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized
CVE-2023-23752MEDIUMbajo ataque25 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH25 mar 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RIESGO
abrir
GitHub PoC94
Joomla! < 4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMbajo ataque24 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC1
RSA NetWitness Platform EDR Agent / Incorrect Access Control - Code Execution
CVE-2022-4752924 mar 2023
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RIESGO
abrir
GitHub PoC6
test of exploit for CVE-2023-21716
CVE-2023-21716CRITICAL24 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC1
An exploitation demo of Outlook Elevation of Privilege Vulnerability
CVE-2023-23397CRITICALbajo ataque24 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC15
CVE-2023-28432 POC
CVE-2023-28432HIGHbajo ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC
CVE-2023-23397 powershell patch script for Windows 10 and 11
CVE-2023-23397CRITICALbajo ataque24 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC37
MinIO敏感信息泄露漏洞批量扫描poc&exp
CVE-2023-28432HIGHbajo ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC7
CVE-2023-28432,minio未授权访问检测工具
CVE-2023-28432HIGHbajo ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC34
CVE-2023-28434 nuclei templates
CVE-2023-28432HIGHbajo ataque23 mar 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC8
CVE-2023-28343 POC exploit
CVE-2023-2834323 mar 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RIESGO
abrir
GitHub PoC114
Exploit for CVE-2023-27532 against Veeam Backup & Replication
CVE-2023-27532HIGHbajo ataqueransomware23 mar 2023
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RIESGO
abrir
GitHub PoC10
MiniO verify interface sensitive information disclosure vulnerability (CVE-2023-28432)
CVE-2023-28432HIGHbajo ataque23 mar 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
anteriorpágina 277 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.