Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.743 exploits
GitHub PoC
adarshpv9746/Text4shell--Automated-exploit---CVE-2022-42889
CVE-2022-4288907 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC2
yilin1203/CVE-2018-20062
CVE-2018-20062CRITICALbajo ataque07 nov 2022
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir
GitHub PoC3
gcc exploit.c -o exploit -lmnl -lnftnl -no-pie -lpthread
CVE-2022-2586MEDIUMbajo ataque06 nov 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RIESGO
abrir
GitHub PoC2
Unauthenticated RCE in GLPI 10.0.2
CVE-2022-35914CRITICALbajo ataque06 nov 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
GitHub PoC1
Proof of Concept for CVE-2021-29447 written in Python
CVE-2021-29447HIGH06 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC3
Arbitrary file read controller based on CVE-2021-29447
CVE-2021-29447HIGH06 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC7
This repo contains payload for the CVE-2022-36067
CVE-2022-36067CRITICAL05 nov 2022
vm2 vulnerable to Sandbox Escape before v3.9.11
60RIESGO
abrir
GitHub PoC2
CVE-2022-42889 (a.k.a. Text4Shell) RCE Proof of Concept
CVE-2022-4288905 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC7
Script to handle CVE 2022-42889
CVE-2022-4288905 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC1
b-abderrahmane/CVE-2021-29447-POC
CVE-2021-29447HIGH05 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC15
Proof of Concept for CVE-2022-42889 (Text4Shell Vulnerability)
CVE-2022-4288904 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC35
A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692
CVE-2022-31692CRITICAL03 nov 2022
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass v
48RIESGO
abrir
GitHub PoC30
利用sudo提权,只针对cnetos7
CVE-2021-3156HIGHbajo ataque03 nov 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
POCsuite与goland实现华为HG532路由器命令注入CVE-2017-17215 POC
CVE-2017-1721502 nov 2022
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RIESGO
abrir
GitHub PoC2
CVE-2022-42889 Blind-RCE Nuclei Template
CVE-2022-4288902 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC15
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHbajo ataqueransomware01 nov 2022
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC7
python编写的apache路径穿越poc&exp
CVE-2021-41773HIGHbajo ataqueransomware01 nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC9
apache路径穿越漏洞poc&exp
CVE-2021-41773HIGHbajo ataqueransomware01 nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC7
SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit
CVE-2017-7494CRITICALbajo ataqueransomware01 nov 2022
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC4
By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:
CVE-2018-14847CRITICALbajo ataque31 oct 2022
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC2
This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication
CVE-2022-1040CRITICALbajo ataque30 oct 2022
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RIESGO
abrir
GitHub PoC1
jehovah2002/CVE-2021-4034-pwnkit
CVE-2021-4034HIGHbajo ataque30 oct 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC17
POC for CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability.
CVE-2022-21907CRITICAL29 oct 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC11
hughink/CVE-2022-40684
CVE-2022-40684CRITICALbajo ataqueransomware28 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC2
Exploit Fortigate - CVE-2022-40684
CVE-2022-40684CRITICALbajo ataqueransomware27 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC14
An authentication bypass using an alternate path or channel in Fortinet product
CVE-2022-40684CRITICALbajo ataqueransomware27 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC14
CVE-2023-29478 - BiblioCraft File Manipulation/Remote Code Execution exploit affecting BiblioCraft versions prior to v2.4.6
CVE-2023-29478CRITICAL27 oct 2022
BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to a
48RIESGO
abrir
GitHub PoC5
pdf_info <= 0.5.3 OS Command Injection
CVE-2022-36231CRITICAL26 oct 2022
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
48RIESGO
abrir
GitHub PoC9
qingsiweisan/CVE-2022-40684
CVE-2022-40684CRITICALbajo ataqueransomware26 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC5
Exploit Samba smbd 3.0.20-Debian
CVE-2007-244725 oct 2022
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
anteriorpágina 291 / 459siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.