Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC5
WAGO Remote Exploit Tool for CVE-2023-1698
CVE-2023-1698CRITICAL15 sep 2023
WAGO: WBM Command Injection in multiple products
85RIESGO
abrir
GitHub PoC
Anthony1500/CVE-2022-40684
CVE-2022-40684CRITICALbajo ataqueransomware14 sep 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC
CVE-2018-1000861 Exploit
CVE-2018-1000861CRITICALbajo ataque13 sep 2023
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RIESGO
abrir
GitHub PoC1
CVE-2023-43481
CVE-2023-43481CRITICAL13 sep 2023
An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote att
48RIESGO
abrir
GitHub PoC3
Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability
CVE-2023-38831HIGHbajo ataqueransomware12 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC9
CVE-2023-38831 WinRaR Exploit Generator
CVE-2023-38831HIGHbajo ataqueransomware12 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
CVE-2022-4063CRITICAL11 sep 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RIESGO
abrir
GitHub PoC
ช่องโหว่ CVE-2023-35674 *สถานะ: ยังไม่เสร็จ*
CVE-2023-35674HIGHbajo ataque11 sep 2023
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RIESGO
abrir
GitHub PoC1
Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.
CVE-2018-1676311 sep 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC
Development of an exploit for privilege escalation in Windows systems ( NT / 2k / XP / 2K3 / VISTA / 2k8 / 7 ) using the vulnerability CVE-2010-0232
CVE-2010-0232HIGHbajo ataque11 sep 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RIESGO
abrir
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI
CVE-2023-015911 sep 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RIESGO
abrir
GitHub PoC
caopengyan/CVE-2023-2825
CVE-2023-2825CRITICAL10 sep 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
GitHub PoC
0xZon/CVE-2022-46169-Exploit
CVE-2022-46169CRITICALbajo ataque10 sep 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
davidholiday/CVE-2007-4559
CVE-2007-4559CRITICAL10 sep 2023
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RIESGO
abrir
GitHub PoC
simulation experiment of Curveball (CVE-2020-0601) attacks under ECQV implicit certificates with Windows-like verifiers
CVE-2020-0601HIGHbajo ataque09 sep 2023
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC
RCE PoC for Apache Commons Text vuln
CVE-2022-4288909 sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
Hikikan/CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware08 sep 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC28
jakabakos/CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE
CVE-2023-27524HIGHbajo ataque08 sep 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC9
A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak
CVE-2017-822508 sep 2023
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RIESGO
abrir
GitHub PoC7
An exploit for OpenTSDB <= 2.4.1 cmd injection (CVE-2023-36812/CVE-2023-25826) written in Fortran
CVE-2023-36812CRITICAL07 sep 2023
Remote Code Execution in OpenTSDB
68RIESGO
abrir
GitHub PoC2
SUPRAAA-1337/CVE-2021-20021
CVE-2021-20021CRITICALbajo ataqueransomware07 sep 2023
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account
100RIESGO
abrir
GitHub PoC
Quick exploit builder for CVE-2023-38831, a vulnerability that affects WinRAR versions before 6.23.
CVE-2023-38831HIGHbajo ataqueransomware07 sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
This is a PoC for CVE-2023-27372 and spawns a fully interactive shell.
CVE-2023-27372CRITICAL07 sep 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC
Text4Shell
CVE-2022-4288906 sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC47
CVE-2023-4634
CVE-2023-4634CRITICAL05 sep 2023
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
85RIESGO
abrir
GitHub PoC
Ijinleife/CVE-2019-14287
CVE-2019-1428705 sep 2023
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
Generate Seralize Payload for CVE-2019-0604 for Sharepoint 2010 SP2 .net 3.5
CVE-2019-0604CRITICALbajo ataqueransomware05 sep 2023
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
GitHub PoC1
Script to exploit CVE-2023-38035
CVE-2023-38035CRITICALbajo ataqueransomware05 sep 2023
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RIESGO
abrir
GitHub PoC
A bash script for easyly exploiting ImageMagick Arbitrary File Read Vulnerability CVE-2022-44268
CVE-2022-44268MEDIUM05 sep 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC
asepsaepdin/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque05 sep 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
anteriorpágina 259 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.