Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC8
Local privilege escalation exploit for Android Binder bug CVE-2020-0041 (Pixel 3a)
CVE-2020-0041HIGHbajo ataque14 ago 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RIESGO
abrir
GitHub PoC
This is a combination of the zerologon_tester.py code (https://raw.githubusercontent.com/SecuraBV/CVE-2020-1472/master/zerologon_tester.py) and the tool evil-winrm to get a shell.
CVE-2020-1472MEDIUMbajo ataqueransomware14 ago 2023
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC2
CVE-2022-44268_By_Kyokito
CVE-2022-44268MEDIUM13 ago 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC1
A PoC exploit for CVE-2021-34621 - WordPress Privilege Escalation
CVE-2021-34621CRITICAL12 ago 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir
GitHub PoC
CVE-2023-4174 PoC
CVE-2023-4174LOW11 ago 2023
mooSocial mooStore cross site scripting
43RIESGO
abrir
GitHub PoC1
CVE-2023-33246 POC
CVE-2023-33246CRITICALbajo ataque11 ago 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC3
Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527
CVE-2023-39526CRITICAL10 ago 2023
PrestaShopSQL manager vulnerability (potential RCE)
48RIESGO
abrir
GitHub PoC
yosef0x01/CVE-2023-21752
CVE-2023-21752HIGH10 ago 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC65
mandiant/citrix-ioc-scanner-cve-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware10 ago 2023
Unauthenticated remote code execution
100RIESGO
abrir
GitHub PoC52
PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2
CVE-2023-38408CRITICAL09 ago 2023
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
CVE-2021-34621CRITICAL09 ago 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir
GitHub PoC
Campcodes Online Matrimonial Website System 3.3 Cross Site Scripting
CVE-2023-3911507 ago 2023
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RIESGO
abrir
GitHub PoC9
CVE exploitation for WebKit jsc CVE-2018-4416
CVE-2018-441607 ago 2023
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RIESGO
abrir
GitHub PoC
Original Exploit Source: https://www.exploit-db.com/exploits/46635
CVE-2019-905307 ago 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC2
Running this exploit on a vulnerable system allows a local attacker to gain a root shell on the machine.
CVE-2023-22809HIGH06 ago 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC1
rwincey/cve-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware06 ago 2023
Unauthenticated remote code execution
100RIESGO
abrir
GitHub PoC
MrE-Fog/jboss-_CVE-2017-12149
CVE-2017-12149CRITICALbajo ataqueransomware06 ago 2023
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC3
This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on Ubuntu 5.8.0-48-generic and COS 5.4.89+. Use responsibly and ethically.
CVE-2021-22555HIGHbajo ataque05 ago 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
GitHub PoC1
passwa11/CVE-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware05 ago 2023
Unauthenticated remote code execution
100RIESGO
abrir
GitHub PoC1
isacaya/CVE-2019-11358
CVE-2019-1135805 ago 2023
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir
GitHub PoC2
Exim < 4.90.1 RCE Vulnerability remake for Python3 with arguments passed from CLI
CVE-2018-6789CRITICALbajo ataqueransomware05 ago 2023
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
GitHub PoC2
Perform With Massive Authentication Bypass (Wordpress Mstore-API)
CVE-2023-2732CRITICAL05 ago 2023
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
GitHub PoC1
Quick PoC checker for common configurations that might be available via directory traversal due to CVE-2013-3827
CVE-2013-382705 ago 2023
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RIESGO
abrir
GitHub PoC
Vulnerable environment of CVE-2020-17530 (S2-061) for testing
CVE-2020-17530CRITICALbajo ataque04 ago 2023
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
CVE-2013-2251CRITICALbajo ataque04 ago 2023
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir
GitHub PoC2
CVE-2023-37979 PoC and Checker
CVE-2023-37979HIGH04 ago 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
61RIESGO
abrir
GitHub PoC
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor Homepage: https://github.com/pluck-cms/pluck # Version: 4.7.16 # Tested on Ubuntu 20.04.3 LTS # CVE: CVE-2022-26965
CVE-2022-2696504 ago 2023
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RIESGO
abrir
GitHub PoC4
Remote Unauthenticated API Access Vulnerability in MobileIron Core 11.2 and older
CVE-2023-35082CRITICALbajo ataqueransomware04 ago 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RIESGO
abrir
GitHub PoC4
Exploit CVE-2021-41773 and CVE-2021-42013
CVE-2021-41773HIGHbajo ataqueransomware02 ago 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
726232111/CVE-2023-28252
CVE-2023-28252HIGHbajo ataqueransomware02 ago 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir
anteriorpágina 263 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.