Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC346
api0cradle/CVE-2023-23397-POC-Powershell
CVE-2023-23397CRITICALbajo ataque16 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Automate JWT Exploit (CVE-2018-0114)
CVE-2018-011416 mar 2023
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC7
FortiOS buffer overflow vulnerability
CVE-2022-42475CRITICALbajo ataqueransomware16 mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
GitHub PoC2
Proof of concept exploit code for CVE-2020-7388, an unauthenticated RCE as SYSTEM on Sage X3's AdxDSrv Service
CVE-2020-7388CRITICAL15 mar 2023
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
85RIESGO
abrir
GitHub PoC15
Windows Network File System Remote exploit for CVE-2022-30136
CVE-2022-30136CRITICAL15 mar 2023
Windows Network File System Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC159
Exploit for the CVE-2023-23397
CVE-2023-23397CRITICALbajo ataque15 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Batch scanning site.
CVE-2020-3187CRITICAL14 mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RIESGO
abrir
GitHub PoC1
Implementation of FOLLINA-CVE-2022-30190
CVE-2022-30190HIGHbajo ataqueransomware14 mar 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
An educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft
CVE-2021-44228CRITICALbajo ataqueransomware14 mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
A Tool for scanning CVE-2017-9841 with multithread
CVE-2017-9841CRITICALbajo ataque13 mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC4
CVE-2022-22963 RCE PoC in python
CVE-2022-22963CRITICALbajo ataque13 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC1
Syd-SydneyJr/CVE-2021-45010
CVE-2021-4501013 mar 2023
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RIESGO
abrir
GitHub PoC1
Demonstrable Proof of Concept Exploit for Spring4Shell Vulnerability (CVE-2022-22965)
CVE-2022-22965CRITICALbajo ataque12 mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC26
CVE-2023-21839工具
CVE-2023-21839HIGHbajo ataque11 mar 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
GitHub PoC
python 2.7
CVE-2023-23752MEDIUMbajo ataque11 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC1
Laravel RCE CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware11 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC15
This is poc of CVE-2022-46169 authentication bypass and remote code execution
CVE-2022-46169CRITICALbajo ataque11 mar 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
h1bAna/CVE-2017-5123
CVE-2017-512311 mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
GitHub PoC
ahiahai242/CVE-2017-5123
CVE-2017-512311 mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
GitHub PoC
FortiRecorder Denial of Service Exploit (CVE-2022-41333)
CVE-2022-41333MEDIUM10 mar 2023
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RIESGO
abrir
GitHub PoC
Microsoft Word 远程代码执行漏洞
CVE-2023-21716CRITICAL10 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC11
Tomcat PUT方法任意文件写入(CVE-2017-12615)exp
CVE-2017-12615HIGHbajo ataqueransomware10 mar 2023
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC4
Open Web Analytics 1.7.3 - Remote Code Execution
CVE-2022-2463709 mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
GitHub PoC135
Windows LPE exploit for CVE-2022-37969
CVE-2022-37969HIGHbajo ataque09 mar 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
sei-fish/CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware09 mar 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC2
CVE-2019-15107 图形化测试程序
CVE-2019-15107CRITICALbajo ataqueransomware09 mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC4
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHbajo ataqueransomware09 mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC7
Mass Auto Exploit CVE-2022-4395 Unauthenticated Arbitrary File Upload
CVE-2022-4395CRITICAL09 mar 2023
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
GitHub PoC2
Tenda f3 Malformed HTTP Request Header Processing Vulnerability.
CVE-2020-35391CRITICAL09 mar 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RIESGO
abrir
GitHub PoC4
SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.
CVE-2018-15473MEDIUM09 mar 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
anteriorpágina 279 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.