Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
77.533 exploits
GitHub PoC2
CVE-2016-2098 POC
CVE-2016-209824 sep 2022
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-39197MEDIUMbajo ataque24 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC3
You can find a python script to exploit the vulnerability on Bitbucket related CVE-2022-36804.
CVE-2022-36804HIGHbajo ataque24 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC1
purple-WL/Cobaltstrike-RCE-CVE-2022-39197
CVE-2022-39197MEDIUMbajo ataque24 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC17
Cobalt Strike RCE CVE-2022-39197
CVE-2022-39197MEDIUMbajo ataque24 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-36804HIGHbajo ataque24 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC
PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHbajo ataque24 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
Exploit-DB
Teleport v10.1.1 - Remote Code Execution (RCE)
CVE-2022-36633remotemultiple23 sep 2022
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ss
35RIESGO
abrir
Exploit-DB
TP-Link Tapo c200 1.1.15 - Remote Code Execution (RCE)
CVE-2021-4045CRITICALwebappshardware23 sep 2022
TP-LINK Tapo C200 remote code execution vulnerability
70RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHbajo ataque23 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
Exploit-DBVexDay Proof
Wordpress Plugin WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS)
CVE-2022-2941MEDIUMwebappsphp23 sep 2022
WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
33RIESGO
abrir
GitHub PoC46
CVE-2022-39197(CobaltStrike XSS <=4.7) POC
CVE-2022-39197MEDIUMbajo ataque23 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-39197MEDIUMbajo ataque23 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
Exploit-DB
Feehi CMS 2.1.1 - Remote Code Execution (Authenticated)
CVE-2022-34140webappsphp23 sep 2022
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to
23RIESGO
abrir
GitHub PoC4
PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHbajo ataque23 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC3
WSO2 Arbitrary File Upload to Remote Command Execution (RCE)
CVE-2022-29464CRITICALbajo ataqueransomware22 sep 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC
cobaltstrike4.5版本破/解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等
CVE-2022-39197MEDIUMbajo ataque22 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC73
cve-2022-39197 poc
CVE-2022-39197MEDIUMbajo ataque22 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALbajo ataqueransomware22 sep 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC3
PoC for exploiting CVE-2019-2729 on WebLogic
CVE-2019-2729CRITICAL22 sep 2022
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RIESGO
abrir
Metasploit600
mySCADA MyPRO Authenticated Command Injection (CVE-2023-28384)
CVE-2023-28384HIGH22 sep 2022
CVE-2023-28384
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-2729CRITICAL22 sep 2022
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RIESGO
abrir
GitHub PoC
For detection of sitecore RCE - CVE-2021-42237
CVE-2021-42237CRITICALbajo ataqueransomware22 sep 2022
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-39197MEDIUMbajo ataque22 sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-856221 sep 2022
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC2
MoCh3n/CVE-2015-5531-POC
CVE-2015-553121 sep 2022
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RIESGO
abrir
GitHub PoC1
Caihuar/Joomla-cve-2015-8562
CVE-2015-856221 sep 2022
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC7
Bitbucket CVE-2022-36804 unauthenticated remote command execution
CVE-2022-36804HIGHbajo ataque21 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-36804HIGHbajo ataque21 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC1
CVE-2021-44228 POC / Example
CVE-2021-44228CRITICALbajo ataqueransomware21 sep 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
anteriorpágina 551 / 2585siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.