Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
13.743 exploits
GitHub PoC
Vulnerable configuration Apache HTTP Server version 2.4.49/2.4.50
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗GitHub PoC★ 1
A write-up of my (so far inconclusive) look into CVE-2022-31691
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI
48RIESGO
abrir ↗GitHub PoC★ 2
Abdulazizalsewedy/CVE-2021-29447
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir ↗GitHub PoC★ 2
A massive scanner for CVE-2021-34473 Microsoft Exchange Windows Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 1
Resources required for building Pluralsight CVE-2022-0847 lab
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC★ 3
A Golang program to automate the execution of CVE-2021-29447
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir ↗GitHub PoC★ 1
qq87234770/CVE-2022-22947
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir ↗GitHub PoC★ 4
FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir ↗GitHub PoC★ 3
Social WarFare Plugin (<=3.5.2) Remote Code Execution
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir ↗GitHub PoC
fall2022 secure coding CVE-2019-13272 : Linux Kernel Improper Privilege Management Vulnerability
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗GitHub PoC★ 7
mega8bit/exploit_cve-2021-29447
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir ↗GitHub PoC★ 3
Microsoft Exchange Server Remote Code Execution Vulnerability.
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 7
RCE exploit for WSO2
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir ↗GitHub PoC★ 256
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗GitHub PoC★ 1
CyberKimathi/Py3-CVE-2017-0785
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir ↗GitHub PoC★ 256
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗GitHub PoC
ivilpez/cve-2017-16995.c
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗GitHub PoC★ 359
Unsigned driver loader using CVE-2018-19320
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir ↗GitHub PoC★ 109
Zimbra <9.0.0.p27 RCE
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RIESGO
abrir ↗GitHub PoC★ 4
Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir ↗GitHub PoC
Implementation of CVE-2022-30190 in C
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Joanmei/CVE-2017-0785
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir ↗GitHub PoC
SPRING DATA REST CVE-2017-8046 DEMO
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir ↗GitHub PoC★ 1
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗GitHub PoC★ 1
bantu2301/CVE-2018-16858
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir ↗GitHub PoC★ 2
A simple tool to enumerate users in gitlab
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RIESGO
abrir ↗GitHub PoC★ 1
DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 4
CVE-2022-22965图形化检测工具
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗GitHub PoC
CVE-2022-0824, CVE-2022-0829, File Manger privilege exploit
Improper Access Control to Remote Code Execution in webmin/webmin
78RIESGO
abrir ↗GitHub PoC
The first poc video presenting the sql injection test from ( WordPress Core 5.8.2-'WP_Query' / CVE-2022-21661)
SQL injection in WordPress
78RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.