Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
13.812 exploits
GitHub PoC★ 8
Spring Cloud Function SPEL表达式注入漏洞(CVE-2022-22963)
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir ↗GitHub PoC★ 1
Proof of Concept for exploiting VMware CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC★ 32
Detects attempts and successful exploitation of CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 7
auduongxuan/CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 27
Remote Code Execution Exploit in the RPC Library
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 3
CVE-2022-0185 exploit
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir ↗GitHub PoC★ 19
The poc for CVE-2022-26809 RCE via RPC will be updated here.
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC
VVeakee/CVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir ↗GitHub PoC★ 3
A Zeek detector for CVE-2022-24497.
Windows Network File System Remote Code Execution Vulnerability
60RIESGO
abrir ↗GitHub PoC★ 3
Easy!Appointments < 1.4.3 - Unauthenticated PII (events) disclosure
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RIESGO
abrir ↗GitHub PoC★ 68
CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC
VMware Workspace ONE Access远程代码执行漏洞 / Code By:Jun_sheng
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC★ 16
VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC★ 2
AkuCyberSec/CVE-2017-8917-Joomla-370-SQL-Injection
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗GitHub PoC★ 3
A Zeek CVE-2022-24491 detector.
Windows Network File System Remote Code Execution Vulnerability
60RIESGO
abrir ↗GitHub PoC
exploitation script tryhackme
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗GitHub PoC
Wangsafz/cve-2017-0358.sh
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir ↗GitHub PoC★ 1
Greenwolf/CVE-2022-1175
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
63RIESGO
abrir ↗GitHub PoC★ 4
Greenwolf/CVE-2022-1162
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RIESGO
abrir ↗GitHub PoC★ 23
spring4shell | CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗GitHub PoC★ 3
TerraMaster TOS Unauthenticated Remote Command Execution(RCE) Vulnerability CVE-2022-24990
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RIESGO
abrir ↗GitHub PoC★ 1
mumu2020629/-CVE-2022-22954-scanner
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC
lucksec/VMware-CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC★ 1
corelight/cve-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC★ 12
提供批量扫描URL以及执行命令功能。Workspace ONE Access 模板注入漏洞,可执行任意代码
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC★ 10
PoC for CVE-2022-22954 - VMware Workspace ONE Access Freemarker Server-Side Template Injection
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2022-22954 Açığı test etme
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC★ 279
POC for VMWARE CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC
G01d3nW01f/CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir ↗GitHub PoC★ 11
CVE-2022-22954 is a server-side template injection vulnerability in the VMware Workspace ONE Access and Identity Manager
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.