Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
77.401 exploits
GitHub PoC
CVE-2020-14882 rewritten in PowerShell
CVE-2020-14882CRITICALbajo ataque28 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC37
Cobalt Strike 4.4 猪猪版 去暗桩 去流量特征 beacon仿造真实API服务 修补CVE-2022-39197补丁
CVE-2022-39197MEDIUMbajo ataque28 abr 2023
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque28 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC
This repository contains a python script that will handle the majority of the dompdf cached font exploit (CVE-2022-28368), all you need to do is create the request
CVE-2022-2836828 abr 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RIESGO
abrir
GitHub PoC6
A Python PoC of CVE-2022-21661, inspired from z92g's Go PoC
CVE-2022-21661HIGH27 abr 2023
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC11
Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具
CVE-2023-27524HIGHbajo ataque27 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-42475CRITICALbajo ataqueransomware27 abr 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
GitHub PoC3
Apache Superset Auth Bypass Vulnerability CVE-2023-27524.
CVE-2023-27524HIGHbajo ataque27 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-21661HIGH27 abr 2023
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC
natceil/cve-2022-42475
CVE-2022-42475CRITICALbajo ataqueransomware27 abr 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27524HIGHbajo ataque27 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC
PrestaShop <1.7.8.9 Fix for CVE-2023-30839 and CVE-2023-30545
CVE-2023-30839CRITICAL27 abr 2023
PrestaShop vulnerable to SQL filter bypass leading to arbitrary write requests using "SQL Manager"
48RIESGO
abrir
GitHub PoC2
A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.
CVE-2022-0847HIGHbajo ataque26 abr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-36845CRITICALbajo ataque26 abr 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque26 abr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC19
A collection of resources and information about CVE-2023-2033
CVE-2023-2033HIGHbajo ataque26 abr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RIESGO
abrir
Exploit-DB
PaperCut NG/MG 22.0.4 - Authentication Bypass
CVE-2023-27350CRITICALbajo ataqueransomwarewebappsmultiple25 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALbajo ataqueransomware25 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-22621CRITICAL25 abr 2023
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RIESGO
abrir
Exploit-DB
Sophos Web Appliance 4.3.10.4 - Pre-auth command injection
CVE-2023-1671CRITICALbajo ataquewebappsphp25 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
GitHub PoC8
Exploit for Papercut CVE-2023-27350. [+] Reverse shell [+] Mass checking
CVE-2023-27350CRITICALbajo ataqueransomware25 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC
Check for CVE-2014-0160
CVE-2014-0160HIGHbajo ataque25 abr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC113
Basic PoC for CVE-2023-27524: Insecure Default Configuration in Apache Superset
CVE-2023-27524HIGHbajo ataque25 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
Exploit-DB
KodExplorer 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUMwebappsphp25 abr 2023
kalcaddle KodExplorer cross-site request forgery
33RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque25 abr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
2022 Spring Prof. 謝續平
CVE-2022-21907CRITICAL25 abr 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
ShyTangerine/cve-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware25 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALbajo ataqueransomware25 abr 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC
UnrealIRCd 3.2.8.1 backdoor command execution exploit in Python 3 (CVE-2010-2075).
CVE-2010-207525 abr 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
GitHub PoC1
Fix URL containing SPACES after Apache upgrade CVE-2023-25690
CVE-2023-25690CRITICAL25 abr 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RIESGO
abrir
anteriorpágina 503 / 2581siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.