Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
13.812 exploits
GitHub PoC
Script to check for Spring4Shell vulnerability
CVE-2022-22965CRITICALbajo ataque11 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC4
Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin
CVE-2022-22965CRITICALbajo ataque11 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC4
aniqfakhrul/CVE-2022-22954
CVE-2022-22954CRITICALbajo ataqueransomware11 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC
G01d3nW01f/CVE-2022-22963
CVE-2022-22963CRITICALbajo ataque11 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC2
burp被动扫描插件,目前只有CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque11 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC3
phpunit-shell | CVE_2017-9841
CVE-2017-9841CRITICALbajo ataque09 abr 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC
fransvanbuul/CVE-2022-22965-susceptibility
CVE-2022-22965CRITICALbajo ataque09 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
mappl3/CVE-2019-0841
CVE-2019-0841HIGHbajo ataqueransomware09 abr 2022
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
GitHub PoC1
Ported golang version of dirtycow.c
CVE-2016-5195HIGHbajo ataque08 abr 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测
CVE-2019-379907 abr 2022
Directory Traversal with spring-cloud-config-server
60RIESGO
abrir
GitHub PoC101
Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
Spring4Shell PoC (CVE-2022-22965)
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC3
CalumHutton/CVE-2022-22965-PoC_Payara
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
tmatejicek/CVE-2015-1397
CVE-2015-139707 abr 2022
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir
GitHub PoC6
CVE-2022-22965 pocsuite3 POC
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC63
CVE-2022-22965写入冰蝎webshell脚本
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC2
irgoncalves/irule-cve-2022-22965
CVE-2022-22965CRITICALbajo ataque06 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
🚨 Exploit the CVE-2025-49844 Redis Lua interpreter UAF vulnerability to execute arbitrary shellcode and gain persistent backdoor access.
CVE-2025-49844CRITICAL06 abr 2022
Redis Lua Use-After-Free may lead to remote code execution
85RIESGO
abrir
GitHub PoC2
Navigate CMS <= 2.9.4 - Server-Side Request Forgery (Authenticated)
CVE-2022-2811706 abr 2022
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap
43RIESGO
abrir
GitHub PoC2
The demo code showing the recent Spring4Shell RCE (CVE-2022-22965)
CVE-2022-22965CRITICALbajo ataque06 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
sh-ubh/CVE-2018-1002105
CVE-2018-1002105CRITICAL06 abr 2022
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
GitHub PoC3
Unquoted Service Path privilege escalation vulnerability in Sherpa Connector Service.
CVE-2022-2390906 abr 2022
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might
23RIESGO
abrir
GitHub PoC12
Spring-Cloud-Spel-RCE
CVE-2022-22947CRITICALbajo ataque06 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC2
Dirty Pipe Vulnerability Detection Script - RHSB-2022-002 Dirty Pipe - kernel arbitrary file manipulation - (CVE-2022-0847)
CVE-2022-0847HIGHbajo ataque06 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC40
CVE-2021-22555 exploit rewritten with pipe primitive
CVE-2021-22555HIGHbajo ataque05 abr 2022
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
GitHub PoC
CVE-2022-22947 reproduce
CVE-2022-22947CRITICALbajo ataque05 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC1
CVE-2022-22963 research
CVE-2022-22963CRITICALbajo ataque05 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC3
Exploit Of Spring4Shell!
CVE-2022-22965CRITICALbajo ataque05 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
Spring Framework RCE Exploit
CVE-2022-22965CRITICALbajo ataque05 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC16
CVE-2022-0185 exploit rewritten with pipe primitive
CVE-2022-0185HIGHbajo ataque05 abr 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
anteriorpágina 320 / 461siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.