Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.743 exploits
GitHub PoC13
Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp
CVE-2021-3129CRITICALbajo ataqueransomware04 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC6
This script is used for automating exploit for Oracle Ebussiness (EBS) for CVE 2022-21587 ( Unauthenticated File Upload For Remote Code Execution)
CVE-2022-21587CRITICALbajo ataqueransomware03 mar 2023
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RIESGO
abrir
GitHub PoC
An exploit for CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware02 mar 2023
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
Checker and exploit for Bluekeep CVE-2019-0708 vulnerability
CVE-2019-0708CRITICALbajo ataqueransomware02 mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
mritunjay-k/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque02 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
🚀 Exploit for Spring core RCE in C [ wip ]
CVE-2022-22965CRITICALbajo ataque02 mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
TheUnknownSoul/CVE-2022-31814
CVE-2022-31814CRITICAL01 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
GitHub PoC
A demonstration of CVE-2022-42889 (text4shell) remote code execution vulnerability
CVE-2022-4288901 mar 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC12
Joomla 未授权访问漏洞 CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque01 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC2
Kubernetes Lab for CVE-2022-42889
CVE-2022-4288928 feb 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC10
BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748
CVE-2023-27746CRITICAL28 feb 2023
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracke
48RIESGO
abrir
GitHub PoC1
cve-2020-0796利用工具集
CVE-2020-0796CRITICALbajo ataqueransomware28 feb 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC5
一键枚举所有用户名以及写入SSH公钥
CVE-2022-40684CRITICALbajo ataqueransomware27 feb 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC
sz-guanx/CVE-2021-32305
CVE-2021-3230527 feb 2023
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search paramet
60RIESGO
abrir
GitHub PoC2
Ozozuz/Magnolia-CMS-6.2.19-Stored-Cross-Site-Scripting-CVE-2022-33098
CVE-2022-3309827 feb 2023
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.
35RIESGO
abrir
GitHub PoC
hhhotdrink/CVE-2021-22205
CVE-2021-22205CRITICALbajo ataqueransomware27 feb 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC3
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
CVE-2022-39952CRITICAL26 feb 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RIESGO
abrir
GitHub PoC16
nmap detection scripts for CVE-2022-45477, CVE-2022-45479, CVE-2022-45482, CVE-2022-45481
CVE-2022-45477CRITICAL26 feb 2023
Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any pre
48RIESGO
abrir
GitHub PoC7
CVE analysis for CVE-2023-0669
CVE-2023-0669HIGHbajo ataqueransomware26 feb 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RIESGO
abrir
GitHub PoC
orsuprasad/CVE-2022-0847-DirtyPipe-Exploits
CVE-2022-0847HIGHbajo ataque26 feb 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
JonPichel/CVE-2017-7358
CVE-2017-735825 feb 2023
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrar
23RIESGO
abrir
GitHub PoC2
yilin1203/CVE-2022-40881
CVE-2022-40881CRITICAL25 feb 2023
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
68RIESGO
abrir
GitHub PoC31
Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion in Python3
CVE-2019-1094524 feb 2023
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RIESGO
abrir
GitHub PoC115
Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)
CVE-2023-21839HIGHbajo ataque24 feb 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
GitHub PoC17
simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose
CVE-2023-23752MEDIUMbajo ataque24 feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC2
未授权访问漏洞
CVE-2023-23752MEDIUMbajo ataque23 feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC1
CVE-2023-23752 poc
CVE-2023-23752MEDIUMbajo ataque23 feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
3ndorph1n/CVE-2021-42756
CVE-2021-42756CRITICAL23 feb 2023
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 a
60RIESGO
abrir
GitHub PoC3
CVE-2023-23752 Joomla 未授权访问漏洞 poc
CVE-2023-23752MEDIUMbajo ataque23 feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC109
POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon
CVE-2022-42475CRITICALbajo ataqueransomware23 feb 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
anteriorpágina 281 / 459siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.