Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.743 exploits
GitHub PoC4
PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHbajo ataque23 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC3
WSO2 Arbitrary File Upload to Remote Command Execution (RCE)
CVE-2022-29464CRITICALbajo ataqueransomware22 sep 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC
cobaltstrike4.5版本破/解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等
CVE-2022-39197MEDIUMbajo ataque22 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC3
PoC for exploiting CVE-2019-2729 on WebLogic
CVE-2019-2729CRITICAL22 sep 2022
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RIESGO
abrir
GitHub PoC73
cve-2022-39197 poc
CVE-2022-39197MEDIUMbajo ataque22 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC
For detection of sitecore RCE - CVE-2021-42237
CVE-2021-42237CRITICALbajo ataqueransomware22 sep 2022
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RIESGO
abrir
GitHub PoC7
Bitbucket CVE-2022-36804 unauthenticated remote command execution
CVE-2022-36804HIGHbajo ataque21 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC1
CVE-2021-44228 POC / Example
CVE-2021-44228CRITICALbajo ataqueransomware21 sep 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALbajo ataqueransomware21 sep 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
MoCh3n/CVE-2015-5531-POC
CVE-2015-553121 sep 2022
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RIESGO
abrir
GitHub PoC1
Caihuar/Joomla-cve-2015-8562
CVE-2015-856221 sep 2022
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC3
CVE-2022-39197
CVE-2022-39197MEDIUMbajo ataque21 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC
dileepdkumar/LayarKacaSiber-CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware20 sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC82
Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.
CVE-2007-4559CRITICAL20 sep 2022
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RIESGO
abrir
GitHub PoC3
CVE-2019-8943 WordPress Crop-Image
CVE-2019-894320 sep 2022
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
GitHub PoC
A critical vulnerability (CVE-2022-36804) in Atlassian Bitbucket Server and Data Center could be exploited by unauthorized attackers to execute malicious code on vulnerable instances.
CVE-2022-36804HIGHbajo ataque20 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC16
Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHbajo ataque20 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC3
CVE-2022-36804 Atlassian Bitbucket Command Injection Vulnerability
CVE-2022-36804HIGHbajo ataque20 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC18
Multithreaded exploit script for CVE-2022-36804 affecting BitBucket versions <8.3.1
CVE-2022-36804HIGHbajo ataque19 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC2
All Credit to MaherAzzouzi (https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit). This is a copy of the exploit for CTFs
CVE-2022-37706HIGH18 sep 2022
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC4
CVE-2022-31814 Exploitation Toolkit.
CVE-2022-31814CRITICAL18 sep 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
GitHub PoC4
CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.
CVE-2019-0708CRITICALbajo ataqueransomware17 sep 2022
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
touchmycrazyredhat/CVE-2022-27925-Revshell
CVE-2022-27925HIGHbajo ataqueransomware17 sep 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir
GitHub PoC
cve-2010-2553复现
CVE-2010-255316 sep 2022
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RIESGO
abrir
GitHub PoC1
pswalia2u/CVE-2020-7246
CVE-2020-724616 sep 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir
GitHub PoC2
A proof of concept for CVE-2022-30190 (Follina).
CVE-2022-30190HIGHbajo ataqueransomware15 sep 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
mightysai1997/cve-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware15 sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
mightysai1997/cve-2021-42013L
CVE-2021-42013CRITICALbajo ataqueransomware15 sep 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
mightysai1997/cve-2021-42013.get
CVE-2021-42013CRITICALbajo ataqueransomware15 sep 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
mightysai1997/CVE-2021-41773S
CVE-2021-41773HIGHbajo ataqueransomware15 sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
anteriorpágina 297 / 459siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.