Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC2
Recreation of the SharePoint PoC for CVE-2023-29357 in C# from LuemmelSec
CVE-2023-29357CRITICALbajo ataqueransomware10 oct 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
WebAccess远程命令执行漏洞(CVE-2017-16720)复现
CVE-2017-1672010 oct 2023
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within th
35RIESGO
abrir
GitHub PoC153
CVE-2023-22515: Confluence Broken Access Control Exploit
CVE-2023-22515CRITICALbajo ataqueransomware10 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC8
Poc for CVE-2023-22515
CVE-2023-22515CRITICALbajo ataqueransomware10 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC164
LPE exploit for CVE-2023-36802
CVE-2023-36802HIGHbajo ataque09 oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
An implementation of a proof-of-concept for CVE-2018-5767 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5767)
CVE-2018-576709 oct 2023
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code
35RIESGO
abrir
GitHub PoC1
xiaoQ1z/CVE-2023-4911
CVE-2023-4911HIGHbajo ataque08 oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC
Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217
CVE-2023-5217HIGHbajo ataque06 oct 2023
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo
83RIESGO
abrir
GitHub PoC9
Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability
CVE-2021-44228CRITICALbajo ataqueransomware06 oct 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
CVE-2021-3560 Bypass su - root
CVE-2021-3560HIGHbajo ataque06 oct 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC16
A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.
CVE-2023-5217HIGHbajo ataque06 oct 2023
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo
83RIESGO
abrir
GitHub PoC
Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217
CVE-2023-5217HIGHbajo ataque06 oct 2023
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo
83RIESGO
abrir
GitHub PoC79
Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence
CVE-2023-22515CRITICALbajo ataqueransomware06 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC3
CVE-2023-41892 - Craft CMS Remote Code Execution (RCE)
CVE-2023-41892CRITICAL06 oct 2023
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC21
A tool for finding vulnerable libwebp(CVE-2023-4863)
CVE-2023-4863HIGHbajo ataque05 oct 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC
whoamins/CVE-2023-42793
CVE-2023-42793CRITICALbajo ataqueransomware05 oct 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC9
PoC of CVE-2023-42793
CVE-2023-42793CRITICALbajo ataqueransomware05 oct 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC392
PoC for CVE-2023-4911
CVE-2023-4911HIGHbajo ataque04 oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC167
CVE-2023-4911 proof of concept
CVE-2023-4911HIGHbajo ataque04 oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC15
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
CVE-2023-4911HIGHbajo ataque04 oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC
Checker for CVE-2022-0441
CVE-2022-044103 oct 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
GitHub PoC4
CVE-2023-36845 PoC script automates the PoC for CVE-2023-36845 targeting Juniper Networks Junos OS's J-Web component on EX and SRX Series devices. It exploits a PHP flaw, allowing remote modification of the PHPRC variable. Successful exploitation can lead to code injection and execution.
CVE-2023-36845CRITICALbajo ataque02 oct 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC1
Analysis of WS_FTP CVE
CVE-2023-40044CRITICALbajo ataqueransomware02 oct 2023
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RIESGO
abrir
GitHub PoC39
A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654
CVE-2023-43654CRITICAL02 oct 2023
TorchServe Server-Side Request Forgery
75RIESGO
abrir
GitHub PoC1
simrotion13/CVE-2023-36845
CVE-2023-36845CRITICALbajo ataque01 oct 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC54
LuemmelSec/CVE-2023-29357
CVE-2023-29357CRITICALbajo ataqueransomware30 sep 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC6
navreet1425/CVE-2021-34621
CVE-2021-34621CRITICAL30 sep 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir
GitHub PoC6
Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129
CVE-2023-4863HIGHbajo ataque30 sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC46
JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit
CVE-2023-42793CRITICALbajo ataqueransomware29 sep 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC5
Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129
CVE-2023-4863HIGHbajo ataque29 sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
anteriorpágina 257 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.