Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
77.231 exploits
GitHub PoC8
Automatic Mass Tool for checking vulnerability in CVE-2022-4060 - WordPress Plugin : User Post Gallery <= 2.19 - Unauthenticated RCE
CVE-2022-4060CRITICAL15 sep 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RIESGO
abrir
GitHub PoC
Anthony1500/CVE-2022-40684
CVE-2022-40684CRITICALbajo ataqueransomware14 sep 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware14 sep 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1000861CRITICALbajo ataque13 sep 2023
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RIESGO
abrir
Metasploit600
Themebleed- Windows 11 Themes Arbitrary Code Execution CVE-2023-38146
CVE-2023-38146HIGH13 sep 2023
Windows Themes Remote Code Execution Vulnerability
48RIESGO
abrir
Metasploit600
Craft CMS unauthenticated Remote Code Execution (RCE)
CVE-2023-41892CRITICAL13 sep 2023
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2018-1000861 Exploit
CVE-2018-1000861CRITICALbajo ataque13 sep 2023
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RIESGO
abrir
GitHub PoC1
CVE-2023-43481
CVE-2023-43481CRITICAL13 sep 2023
An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote att
48RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware12 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware12 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC9
CVE-2023-38831 WinRaR Exploit Generator
CVE-2023-38831HIGHbajo ataqueransomware12 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC3
Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability
CVE-2023-38831HIGHbajo ataqueransomware12 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
CVE-2022-4063CRITICAL11 sep 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676311 sep 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC
Development of an exploit for privilege escalation in Windows systems ( NT / 2k / XP / 2K3 / VISTA / 2k8 / 7 ) using the vulnerability CVE-2010-0232
CVE-2010-0232HIGHbajo ataque11 sep 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RIESGO
abrir
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI
CVE-2023-015911 sep 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4063CRITICAL11 sep 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-015911 sep 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RIESGO
abrir
GitHub PoC
ช่องโหว่ CVE-2023-35674 *สถานะ: ยังไม่เสร็จ*
CVE-2023-35674HIGHbajo ataque11 sep 2023
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RIESGO
abrir
VulnCheck XDB
local
CVE-2010-0232HIGHbajo ataque11 sep 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RIESGO
abrir
GitHub PoC1
Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.
CVE-2018-1676311 sep 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque10 sep 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
davidholiday/CVE-2007-4559
CVE-2007-4559CRITICAL10 sep 2023
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RIESGO
abrir
GitHub PoC
0xZon/CVE-2022-46169-Exploit
CVE-2022-46169CRITICALbajo ataque10 sep 2023
Unauthenticated Command Injection
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-2825CRITICAL10 sep 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque10 sep 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
caopengyan/CVE-2023-2825
CVE-2023-2825CRITICAL10 sep 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
GitHub PoC
simulation experiment of Curveball (CVE-2020-0601) attacks under ECQV implicit certificates with Windows-like verifiers
CVE-2020-0601HIGHbajo ataque09 sep 2023
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC
RCE PoC for Apache Commons Text vuln
CVE-2022-4288909 sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-1389HIGHbajo ataque09 sep 2023
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RIESGO
abrir
anteriorpágina 465 / 2575siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.