Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.743 exploits
GitHub PoC
CVE-2020-0796-利用工具
CVE-2020-0796CRITICALbajo ataqueransomware15 dic 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
A Proof of Concept for the CVE-2021-27928 flaw exploitation
CVE-2021-2792814 dic 2022
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RIESGO
abrir
GitHub PoC3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2021-1497CRITICALbajo ataque13 dic 2022
Cisco HyperFlex HX Command Injection Vulnerabilities
100RIESGO
abrir
GitHub PoC3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2019-11510CRITICALbajo ataqueransomware13 dic 2022
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2020-5902CRITICALbajo ataqueransomware13 dic 2022
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC3
Improper access control in SAP NetWeaver Process Integration
CVE-2022-41272CRITICAL13 dic 2022
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se
48RIESGO
abrir
GitHub PoC
CVE-2020-16846
CVE-2020-16846CRITICALbajo ataque12 dic 2022
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RIESGO
abrir
GitHub PoC
KaviDk/CVE-2019-6447-in-Mobile-Application
CVE-2019-644712 dic 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RIESGO
abrir
GitHub PoC
Educational Follina PoC Tool
CVE-2022-30190HIGHbajo ataqueransomware12 dic 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
devengpk/CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque12 dic 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC7
CVE-2021-3129 Exploit Checker By ./MrMad
CVE-2021-3129CRITICALbajo ataqueransomware10 dic 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC36
POC of CVE-2022-36537
CVE-2022-36537HIGHbajo ataqueransomware09 dic 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RIESGO
abrir
GitHub PoC9
CVE-2022-36537
CVE-2022-36537HIGHbajo ataqueransomware09 dic 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RIESGO
abrir
GitHub PoC20
text4shell(CVE-2022-42889) BurpSuite Scanner
CVE-2022-4288909 dic 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC89
[PoC] Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom)
CVE-2022-45025CRITICAL09 dic 2022
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi
60RIESGO
abrir
GitHub PoC
Scan IP ranges for IP's vulnerable to the F5 Big IP exploit (CVE-2022-1388)
CVE-2022-1388CRITICALbajo ataqueransomware09 dic 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC47
CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.
CVE-2022-46169CRITICALbajo ataque08 dic 2022
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC5
PHPunit Checker CVE-2017-9841 By MrMad
CVE-2017-9841CRITICALbajo ataque07 dic 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque07 dic 2022
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC1
CVE-2022-42889 - Text4Shell exploit
CVE-2022-4288907 dic 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
For CVE-2022-33891 Apache Spark: Emulation and Detection by West Shepherd
CVE-2022-33891HIGHbajo ataque06 dic 2022
Apache Spark shell command injection vulnerability via Spark UI
100RIESGO
abrir
GitHub PoC1
amitlttwo/CVE-2022-1388
CVE-2022-1388CRITICALbajo ataqueransomware06 dic 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC
Spring-CVE-2010-1622
CVE-2010-162205 dic 2022
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RIESGO
abrir
GitHub PoC1
Exploit for path transversal vulnerability in apache
CVE-2021-41773HIGHbajo ataqueransomware05 dic 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Exploit from perception point
CVE-2016-072804 dic 2022
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC
XiangSi-Howard/CTF---CVE-2011-2523
CVE-2011-252303 dic 2022
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC5
CVE-2022-24112_POC
CVE-2022-24112CRITICALbajo ataque03 dic 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC1
JoshMorrison99/CVE-2016-3714
CVE-2016-3714HIGHbajo ataque02 dic 2022
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir
GitHub PoC
lkduy2602/Detecting-CVE-2018-15708-Vulnerabilities
CVE-2018-1570801 dic 2022
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RIESGO
abrir
GitHub PoC2
Exchange CVE '22
CVE-2022-41082HIGHbajo ataqueransomware01 dic 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 288 / 459siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.