Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.727 exploits
GitHub PoC1
MinIO Information Disclosure Vulnerability scanner by metasploit
CVE-2023-28432HIGHbajo ataque27 may 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC2
Exploit for Bad Binder
CVE-2019-2215HIGHbajo ataque27 may 2023
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC2
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp
CVE-2022-22947CRITICALbajo ataque26 may 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC1
PoC for login with password hash in STARFACE
CVE-2023-33243HIGH26 may 2023
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RIESGO
abrir
GitHub PoC
Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function
CVE-2022-22963CRITICALbajo ataque25 may 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC6
MStore API <= 3.9.2 - Authentication Bypass
CVE-2023-2732CRITICAL25 may 2023
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
GitHub PoC7
Camaleon CMS v2.7.0 contain a Server-Side Template Injection (SSTI) vulnerability
CVE-2023-30145CRITICAL25 may 2023
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RIESGO
abrir
GitHub PoC140
GitLab CVE-2023-2825 PoC. This PoC leverages a path traversal vulnerability to retrieve the /etc/passwd file from a system running GitLab 16.0.0.
CVE-2023-2825CRITICAL25 may 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
GitHub PoC
Vulnerable docker to test for: CVE-2023-32243
CVE-2023-32243CRITICAL24 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC
manavvedawala2/CVE-2023-32243-POC
CVE-2023-32243CRITICAL23 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC
manavvedawala2/CVE-2023-32243-proof-of-concept
CVE-2023-32243CRITICAL23 may 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC30
PoC for CVE-2023-28771 based on Rapid7's excellent writeup
CVE-2023-28771CRITICALbajo ataque23 may 2023
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir
GitHub PoC286
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL22 may 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RIESGO
abrir
GitHub PoC
This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).
CVE-2014-1812HIGHbajo ataqueransomware22 may 2023
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RIESGO
abrir
GitHub PoC1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
CVE-2007-596222 may 2023
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RIESGO
abrir
GitHub PoC
Dockerized POC for CVE-2022-42889 Text4Shell
CVE-2022-4288922 may 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
RCE Unauth in PyLoad <0.5.0b3.dev31
CVE-2023-0297CRITICAL21 may 2023
Code Injection in pyload/pyload
85RIESGO
abrir
GitHub PoC
antisecc/CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque21 may 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
antisecc/CVE-2022-24716
CVE-2022-24716HIGH20 may 2023
Path traversal in Icinga Web 2
78RIESGO
abrir
GitHub PoC
xiaosed/CVE-2023-29919
CVE-2023-29919CRITICAL19 may 2023
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t
75RIESGO
abrir
GitHub PoC1
Golang implementation of ThinVNC exploit CVE-2019-17662. For educational purposes only.
CVE-2019-1766219 may 2023
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir
GitHub PoC
Proof of Concept about a XSS Stored in SCM Manager 1.2 <= 1.60
CVE-2023-33829MEDIUM19 may 2023
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RIESGO
abrir
GitHub PoC59
CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/
CVE-2023-21554CRITICAL18 may 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RIESGO
abrir
GitHub PoC2
CVE-2023-31702 is an authenticated SQL Injection vulnerability discovered in MicroWorld Technologies eScan Management Console version 14.0.1400.2281.
CVE-2023-31702HIGH17 may 2023
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
41RIESGO
abrir
GitHub PoC4
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Edit User functionality of the Microworld Technologies eScan Management Console (version 14.0.1400.2281).
CVE-2023-31703CRITICAL17 may 2023
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RIESGO
abrir
GitHub PoC24
PoC for CVE-2023-20126
CVE-2023-20126CRITICAL17 may 2023
Cisco SPA112 2-Port Phone Adapters Remote Command Execution Vulnerability
60RIESGO
abrir
GitHub PoC
Exploit to cve-2023-1671. So there is a test and exploitation function. The test sends a ping request to the dnslog domain from the vulnerable site. If the ping passes, the vulnerability exists, if it doesn't, then cve-2023-1671 is missing. The exploit function, on the other hand, sends a request with your command to the server.
CVE-2023-1671CRITICALbajo ataque17 may 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
GitHub PoC11
POC for the CVE-2022-36944 vulnerability exploit
CVE-2022-36944CRITICAL16 may 2023
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There i
48RIESGO
abrir
GitHub PoC51
Vulnerabilities Exploitation On Ubuntu 22.04
CVE-2023-0386HIGHbajo ataque16 may 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC
school project
CVE-2019-15107CRITICALbajo ataqueransomware15 may 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
anteriorpágina 271 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.