Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.734 exploits
GitHub PoC3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
CVE-2023-30256MEDIUM10 abr 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RIESGO
abrir
GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
CVE-2023-28432HIGHbajo ataque09 abr 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC33
Perform With Mass Exploiter In Joomla 4.2.8.
CVE-2023-23752MEDIUMbajo ataque09 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
ReachabilityOrg/cve-2022-42889-text4shell-docker
CVE-2022-4288908 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
Ge-Per/Scanner-CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque08 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC2
Clone from gist
CVE-2023-29017CRITICAL07 abr 2023
vm2 Sandbox Escape vulnerability
60RIESGO
abrir
GitHub PoC
jedai47/cve-2018-17182
CVE-2018-1718207 abr 2023
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
GitHub PoC2
POC,EXP,chatGPT for me
CVE-2022-45047CRITICAL07 abr 2023
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RIESGO
abrir
GitHub PoC
jedai47/CVE-2017-16994
CVE-2017-1699407 abr 2023
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RIESGO
abrir
GitHub PoC
Checker help to verify created account or find it's mandat
CVE-2020-6287CRITICALbajo ataque07 abr 2023
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
GitHub PoC
jedai47/CVE-2018-7273
CVE-2018-727307 abr 2023
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RIESGO
abrir
GitHub PoC2
DarokNET/CVE-2023-27100
CVE-2023-27100CRITICAL07 abr 2023
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RIESGO
abrir
GitHub PoC1
POC,EXP,chatGPT for me,只能给一些思路,全部不可用
CVE-2022-21306CRITICAL07 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
48RIESGO
abrir
GitHub PoC8
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
CVE-2023-0669HIGHbajo ataqueransomware06 abr 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RIESGO
abrir
GitHub PoC
BaconCriCRi/PoC-CVE-2022-4939-
CVE-2022-4939CRITICAL06 abr 2023
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
48RIESGO
abrir
GitHub PoC1
CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque06 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC6
CVE-2023-22809 Linux Sudo
CVE-2023-22809HIGH06 abr 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC
qaisarafridi/cve-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware06 abr 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC1
LHXHL/Minio-CVE-2023-28432
CVE-2023-28432HIGHbajo ataque06 abr 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC3
brosck/CVE-2006-3392
CVE-2006-339204 abr 2023
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
GitHub PoC2
CVE-2014-6287
CVE-2014-6287CRITICALbajo ataque04 abr 2023
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC
docker for CVE-2022-42889
CVE-2022-4288904 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC7
Poc for CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque04 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC2
my python poc CVE-2023-24774 and CVE-2023-24775 this sqli cve funadmin
CVE-2023-24775CRITICAL03 abr 2023
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member
53RIESGO
abrir
GitHub PoC1
A vulnerable Spring Boot application that uses log4j and is vulnerable to CVE-2021-44228, CVE-2021-44832, CVE-2021-45046 and CVE-2021-45105
CVE-2021-44228CRITICALbajo ataqueransomware02 abr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Struts2 S2-061 远程命令执行漏洞(CVE-2020-17530)
CVE-2020-17530CRITICALbajo ataque02 abr 2023
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC
devAL3X/CVE-2022-46169_poc
CVE-2022-46169CRITICALbajo ataque01 abr 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
exploit for CVE-2021-22911 in rust
CVE-2021-2291101 abr 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC1
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2022-46169). Run it at your own risk!
CVE-2022-46169CRITICALbajo ataque01 abr 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
lionelmusonza/CVE-2023-26866
CVE-2023-26866CRITICAL01 abr 2023
GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respe
48RIESGO
abrir
anteriorpágina 276 / 458siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.