Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.743 exploits
GitHub PoC
SilasSpringer/CVE-2018-10933
CVE-2018-10933CRITICAL01 dic 2022
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
A Terraform module to launch Rancher 2.6.6 for blog article about CVE-2021-36782
CVE-2021-36782CRITICAL01 dic 2022
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
63RIESGO
abrir
GitHub PoC2
Validation of Arbitrary File Read Vulnerabilities in Dell OpenManage Server Administrator (OMSA) - CVE-2016-4004, CVE-2021-21514 and CVE-2020-5377.
CVE-2020-5377CRITICAL30 nov 2022
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RIESGO
abrir
GitHub PoC2
Validation of Arbitrary File Read Vulnerabilities in Dell OpenManage Server Administrator (OMSA) - CVE-2016-4004, CVE-2021-21514 and CVE-2020-5377.
CVE-2016-400430 nov 2022
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RIESGO
abrir
GitHub PoC3
revanmalang/CVE-2022-1388
CVE-2022-1388CRITICALbajo ataqueransomware30 nov 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC
fei9747/CVE-2017-16995
CVE-2017-1699529 nov 2022
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC
fei9747/CVE-2016-5195
CVE-2016-5195HIGHbajo ataque29 nov 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC1
fei9747/CVE-2021-3493
CVE-2021-3493HIGHbajo ataque29 nov 2022
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC
fei9747/CVE-2021-4034
CVE-2021-4034HIGHbajo ataque29 nov 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC100
clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability CVE-2021-3156 and the fact that for some reasons, Google's afl-fuzz doesn't allow for unlimited argument or option specification.
CVE-2021-3156HIGHbajo ataque28 nov 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
ClemExp/CVE-2022-22965-PoC
CVE-2022-22965CRITICALbajo ataque28 nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
CVE-2022-22965 proof of concept
CVE-2022-22965CRITICALbajo ataque28 nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
CVE-2017-9833 POC
CVE-2017-983325 nov 2022
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read
50RIESGO
abrir
GitHub PoC2
CVE-2022-39197
CVE-2022-39197MEDIUMbajo ataque24 nov 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC13
Apache HTTP-Server 2.4.49-2.4.50 Path Traversal & Remote Code Execution PoC (CVE-2021-41773 & CVE-2021-42013)
CVE-2021-41773HIGHbajo ataqueransomware22 nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC8
PoC for CVE-2021-31166 and CVE-2022-21907
CVE-2022-21907CRITICAL22 nov 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC8
PoC for CVE-2021-31166 and CVE-2022-21907
CVE-2021-31166CRITICALbajo ataque22 nov 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC7
grails/GSSC-CVE-2022-41923
CVE-2022-41923CRITICAL22 nov 2022
Grails Spring Security Core plugin vulnerable to privilege escalation
48RIESGO
abrir
GitHub PoC
dr4g0n23/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware22 nov 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
CVE-2017-9841
CVE-2017-9841CRITICALbajo ataque21 nov 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC1
CVE-1999-1053 Proof-of-Concept Exploit
CVE-1999-105321 nov 2022
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remo
60RIESGO
abrir
GitHub PoC5
Python Script to exploit RCE of CVE-2022-42889
CVE-2022-4288921 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC7
修改版CVE-2022-0847
CVE-2022-0847HIGHbajo ataque21 nov 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
REMOTE CODE EXECUTION found in "OPTILINK OP-XT71000N".
CVE-2020-23583CRITICAL20 nov 2022
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary
48RIESGO
abrir
GitHub PoC
ARBITAR FILE UPLOAD LEADS TO "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor , Escalation of Privileges, etc".
CVE-2020-23591CRITICAL20 nov 2022
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker t
48RIESGO
abrir
GitHub PoC
REMOTE CODE EXECUTION
CVE-2020-23584CRITICAL20 nov 2022
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes ar
60RIESGO
abrir
GitHub PoC8
A Command Line based python tool for exploit Zero-Day vulnerability in MSDT (Microsoft Support Diagnostic Tool) also know as 'Follina' CVE-2022-30190.
CVE-2022-30190HIGHbajo ataqueransomware19 nov 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Vulnerable configuration Apache HTTP Server version 2.4.49/2.4.50
CVE-2021-42013CRITICALbajo ataqueransomware18 nov 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
Vulnerable configuration Apache HTTP Server version 2.4.49
CVE-2021-41773HIGHbajo ataqueransomware18 nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
CVE-2022-0441 - MasterStudy LMS 2.7.6
CVE-2022-044118 nov 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
anteriorpágina 289 / 459siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.