Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
13.812 exploits
GitHub PoC14
This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed "SpringShell".
CVE-2022-22963CRITICALbajo ataque31 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC15
CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit
CVE-2022-22963CRITICALbajo ataque30 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC131
Spring4Shell - Spring Core RCE - CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque30 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC50
CVE-2022-22965 : about spring core rce
CVE-2022-22965CRITICALbajo ataque30 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC377
Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque30 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC3
{ Spring Core 0day CVE-2022-22963 }
CVE-2022-22963CRITICALbajo ataque30 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC9
Kirill89/CVE-2022-22963-PoC
CVE-2022-22963CRITICALbajo ataque30 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC
Spring Cloud Gateway Actuator API SpEL Code Injection.
CVE-2022-22947CRITICALbajo ataque30 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC115
CVE-2022-22963 PoC
CVE-2022-22963CRITICALbajo ataque30 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC34
darryk10/CVE-2022-22963
CVE-2022-22963CRITICALbajo ataque30 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC
CVE-2022-28080
CVE-2022-2808030 mar 2022
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
50RIESGO
abrir
GitHub PoC
scopion/CVE-2022-22947-exp
CVE-2022-22947CRITICALbajo ataque30 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC3
A TLS server using a vendored fork of the Go TLS stack that has renegotation indication extension forcibly disabled.
CVE-2009-3555CRITICAL30 mar 2022
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RIESGO
abrir
GitHub PoC
CVE-2022-28079
CVE-2022-2807930 mar 2022
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
43RIESGO
abrir
GitHub PoC4
Spring Cloud Gateway RCE - CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque30 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC2
Vancomycin-g/CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque29 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC2
Powershell script that dumps Chrome and Edge version to a text file in order to determine if you need to update due to CVE-2022-1096
CVE-2022-1096HIGHbajo ataque29 mar 2022
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corrup
76RIESGO
abrir
GitHub PoC21
CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution
CVE-2019-919329 mar 2022
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC
Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).
CVE-2020-1472MEDIUMbajo ataqueransomware29 mar 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC11
misterxid/watchguard_cve-2022-26318
CVE-2022-26318CRITICALbajo ataque28 mar 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RIESGO
abrir
GitHub PoC
Tankirat/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware28 mar 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
Description of Exploit SMBGhost CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware28 mar 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
chattopadhyaykittu/CVE-2017-0037
CVE-2017-0037HIGHbajo ataque28 mar 2022
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RIESGO
abrir
GitHub PoC354
spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963
CVE-2022-22963CRITICALbajo ataque26 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC
tzwlhack/CVE-2018-20250
CVE-2018-20250HIGHbajo ataqueransomware25 mar 2022
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC2
Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration
CVE-2019-2215HIGHbajo ataque25 mar 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC1
poc for CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque25 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
spasm5/CVE-2018-12326
CVE-2018-1232625 mar 2022
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution
23RIESGO
abrir
GitHub PoC1
This is a exploit code for CVE-2020-8163
CVE-2020-816324 mar 2022
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RIESGO
abrir
GitHub PoC
A quick python exploit for the Nostromo 1.9.6 remote code execution vulnerability. Only takes in host and port of web server as required arguments.
CVE-2019-16278CRITICALbajo ataque24 mar 2022
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
anteriorpágina 323 / 461siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.