Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.743 exploits
GitHub PoC275
CVE-2022-44268 ImageMagick Arbitrary File Read - Payload Generator
CVE-2022-44268MEDIUM02 feb 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC
Unauthenticated SQL Injection - Paid Memberships Pro < 2.9.8 (WordPress Plugin)
CVE-2023-23488CRITICAL02 feb 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir
GitHub PoC
imbas007/Atlassian-Bitbucket-CVE-2022-36804
CVE-2022-36804HIGHbajo ataque02 feb 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC
miko550/CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque02 feb 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC3
Microsoft Exchange CVE-2021-26855&CVE-2021-27065
CVE-2021-26855CRITICALbajo ataqueransomware02 feb 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Trinadh465/linux-4.1.15_CVE-2017-1000371
CVE-2017-100037102 feb 2023
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1
23RIESGO
abrir
GitHub PoC1
Control Web Panel 7 (CWP7) Remote Code Execution (RCE) (CVE-2022-44877) (Unauthenticated)
CVE-2022-44877CRITICALbajo ataque02 feb 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RIESGO
abrir
GitHub PoC18
Cisco SmartInstall Exploit [CVE-2018-0171]
CVE-2018-0171HIGHbajo ataque01 feb 2023
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica
100RIESGO
abrir
GitHub PoC9
CVE-2023-23924 (Dompdf - RCE) PoC
CVE-2023-23924CRITICAL01 feb 2023
URI validation failure on SVG parsing in Dompdf
48RIESGO
abrir
GitHub PoC1
paulotrindadec/CVE-2019-9193
CVE-2019-919301 feb 2023
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC1
Proof of concept for CVE-2022-41220
CVE-2022-41220CRITICAL31 ene 2023
md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE:
48RIESGO
abrir
GitHub PoC17
mistymntncop/CVE-2022-26485
CVE-2022-26485HIGHbajo ataque31 ene 2023
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of at
76RIESGO
abrir
GitHub PoC6
Vulnerability CVE-2021-44228 allows remote code execution without authentication for several versions of Apache Log4j2 (Log4Shell). Attackers can exploit vulnerable servers by connecting over any protocol, such as HTTPS, and sending a specially crafted string.
CVE-2021-44228CRITICALbajo ataqueransomware31 ene 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform c CVE project by @Sn0wAlice
CVE-2021-40113CRITICAL30 ene 2023
Cisco Catalyst PON Series Switches Optical Network Terminal Vulnerabilities
48RIESGO
abrir
GitHub PoC282
Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit
CVE-2023-21608HIGHbajo ataque30 ene 2023
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability
83RIESGO
abrir
GitHub PoC
Joomla JCK Editor 6.4.4 - 'parent' SQL Injection
CVE-2018-1725429 ene 2023
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RIESGO
abrir
GitHub PoC
This is a vulnerability in the Linux kernel that was discovered and disclosed in 2017.
CVE-2017-548729 ene 2023
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
GitHub PoC7
The official exploit for Froxlor Remote Code Execution CVE-2023-0315
CVE-2023-0315HIGH29 ene 2023
Command Injection in froxlor/froxlor
78RIESGO
abrir
GitHub PoC
windows 10 SMB vulnerability
CVE-2020-0796CRITICALbajo ataqueransomware29 ene 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
This script implements a lab automation where I exploit CVE-2021-43798 to steal user secrets and then gain privileges on a Linux system.
CVE-2021-43798HIGHbajo ataque28 ene 2023
Grafana path traversal
100RIESGO
abrir
GitHub PoC
Exploit for CVE-2022-40684 vulnerability
CVE-2022-40684CRITICALbajo ataqueransomware28 ene 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC
vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 2.39 and older. Git for Windows was also patched to address an additional, Windows-specific issue known as CVE-2022-41953.
CVE-2022-41903CRITICAL26 ene 2023
Integer overflow in `git archive`, `git log --format` leading to RCE in git
60RIESGO
abrir
GitHub PoC2
In Paradox Security System IPR512 web panel, an unauthenticated user can input JavaScript string, such as </script> that will overwrite configurations in the file "login.xml" and cause the login form to crash and make it unavailable.
CVE-2023-24709HIGH26 ene 2023
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RIESGO
abrir
GitHub PoC1
Relativ3Pa1n/CVE-2014-2383-LFI-to-RCE-Escalation
CVE-2014-238326 ene 2023
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RIESGO
abrir
GitHub PoC2
DDoS Tool which exploits vulnerability CVE-2004-2449 from vendor GameSpy (now known as OpenSpy). User is prompted for input IP address, and port. (NOTE: Please use this responsibly, I made this as a proof of concept of vulnerability exploitation ONLY. I do not endorse DOSing, DDoSing, or cheating in any way. Use this at your own risk.)
CVE-2004-244925 ene 2023
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial
23RIESGO
abrir
GitHub PoC1
A pwnkit N-Day exploit
CVE-2021-4034HIGHbajo ataque24 ene 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC6
A proof of concept exploit for a wordpress 5.6 media library vulnerability
CVE-2021-29447HIGH24 ene 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC2
Drity Pipe Linux Kernel 1-Day Exploit
CVE-2022-0847HIGHbajo ataque24 ene 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC8
A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects all versions of Bitbucket Server and Data Center released before versions <7.6.17, <7.17.10, <7.21.4, <8.0.3, <8.1.2, <8.2.2, and <8.3.1
CVE-2022-36804HIGHbajo ataque23 ene 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC7
The manage engine mass loader for CVE-2022-47966
CVE-2022-47966CRITICALbajo ataqueransomware23 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
anteriorpágina 284 / 459siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.