Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
77.449 exploits
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware14 mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Batch scanning site.
CVE-2020-3187CRITICAL14 mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RIESGO
abrir
GitHub PoC4
A Tool for scanning CVE-2017-9841 with multithread
CVE-2017-9841CRITICALbajo ataque13 mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALbajo ataque13 mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC1
Syd-SydneyJr/CVE-2021-45010
CVE-2021-4501013 mar 2023
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RIESGO
abrir
Metasploit600
PaperCut PaperCutNG Authentication Bypass
CVE-2023-27350CRITICALbajo ataqueransomware13 mar 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
Metasploit600
Lexmark Device Embedded Web Server RCE
CVE-2023-26068CRITICAL13 mar 2023
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALbajo ataque13 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC4
CVE-2022-22963 RCE PoC in python
CVE-2022-22963CRITICALbajo ataque13 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC1
Demonstrable Proof of Concept Exploit for Spring4Shell Vulnerability (CVE-2022-22965)
CVE-2022-22965CRITICALbajo ataque12 mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC26
CVE-2023-21839工具
CVE-2023-21839HIGHbajo ataque11 mar 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
GitHub PoC1
Laravel RCE CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware11 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC15
This is poc of CVE-2022-46169 authentication bypass and remote code execution
CVE-2022-46169CRITICALbajo ataque11 mar 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
h1bAna/CVE-2017-5123
CVE-2017-512311 mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware11 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
python 2.7
CVE-2023-23752MEDIUMbajo ataque11 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
ahiahai242/CVE-2017-5123
CVE-2017-512311 mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque11 mar 2023
Unauthenticated Command Injection
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-21894MEDIUM11 mar 2023
Secure Boot Security Feature Bypass Vulnerability
33RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMbajo ataque11 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
Microsoft Word 远程代码执行漏洞
CVE-2023-21716CRITICAL10 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
FortiRecorder Denial of Service Exploit (CVE-2022-41333)
CVE-2022-41333MEDIUM10 mar 2023
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware10 mar 2023
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC11
Tomcat PUT方法任意文件写入(CVE-2017-12615)exp
CVE-2017-12615HIGHbajo ataqueransomware10 mar 2023
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-21768HIGH10 mar 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RIESGO
abrir
GitHub PoC4
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHbajo ataqueransomware09 mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC7
Bulk scanner + get config from CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-37969HIGHbajo ataque09 mar 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC2
开源,go多并发批量探测poc,准确率高
CVE-2023-23752MEDIUMbajo ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC2
CVE-2019-15107 图形化测试程序
CVE-2019-15107CRITICALbajo ataqueransomware09 mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
anteriorpágina 519 / 2582siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.