Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.743 exploits
GitHub PoC7
The manage engine mass loader for CVE-2022-47966
CVE-2022-47966CRITICALbajo ataqueransomware23 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
GitHub PoC28
Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.
CVE-2022-47966CRITICALbajo ataqueransomware23 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
GitHub PoC
it is the official Fix of Wordpress CVE-2018-6389.
CVE-2018-638923 ene 2023
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC6
Python exploit for RCE in Wordpress
CVE-2020-25213CRITICALbajo ataque22 ene 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
GitHub PoC165
A script to automate privilege escalation with CVE-2023-22809 vulnerability
CVE-2023-22809HIGH21 ene 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC1
Demo webapp vulnerable to CVE-2022-44900
CVE-2022-44900CRITICAL21 ene 2023
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea
48RIESGO
abrir
GitHub PoC4
Remote Code Execution in Social Warfare Plugin before 3.5.3 for Wordpress.
CVE-2019-9978MEDIUMbajo ataque20 ene 2023
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC
PoC for cve-2022-47966
CVE-2022-47966CRITICALbajo ataqueransomware19 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
GitHub PoC2
A POC on how to exploit CVE-2022-27518
CVE-2022-27518CRITICALbajo ataque17 ene 2023
Unauthenticated remote arbitrary code execution
78RIESGO
abrir
GitHub PoC129
POC for CVE-2022-47966 affecting multiple ManageEngine products
CVE-2022-47966CRITICALbajo ataqueransomware17 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
GitHub PoC1
test for the ioc described for FG-IR-22-398
CVE-2022-42475CRITICALbajo ataqueransomware17 ene 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
GitHub PoC
Project for the Cyberspace Security class.
CVE-2017-891717 ene 2023
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC2
CVE-2014-5460
CVE-2014-546017 ene 2023
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RIESGO
abrir
GitHub PoC
notareaperbutDR34P3r/CVE-2022-40684-Rust
CVE-2022-40684CRITICALbajo ataqueransomware17 ene 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC3
RCE POC for CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque16 ene 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
Exploit For OverlayFS
CVE-2021-3493HIGHbajo ataque16 ene 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC2
Cacti: Unauthenticated Remote Code Execution Exploit in Ruby
CVE-2022-46169CRITICALbajo ataque15 ene 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC2
cbk914/CVE-2022-30525_check
CVE-2022-30525CRITICALbajo ataque15 ene 2023
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
GitHub PoC
nhamle2/CVE-2015-8660
CVE-2015-866015 ene 2023
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir
GitHub PoC3
cbk914/CVE-2022-26134_check
CVE-2022-26134CRITICALbajo ataqueransomware15 ene 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC4
iliass-dahman/CVE-2022-22963-POC
CVE-2022-22963CRITICALbajo ataque15 ene 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC6
Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.
CVE-2022-21661HIGH13 ene 2023
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC1
CVE 2022-45299
CVE-2022-45299CRITICAL13 ene 2023
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi
48RIESGO
abrir
GitHub PoC9
Exploit to CVE-2022-46169 vulnerability
CVE-2022-46169CRITICALbajo ataque13 ene 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC2
cve-2010-1622 Learning Environment
CVE-2010-162211 ene 2023
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RIESGO
abrir
GitHub PoC326
Wh04m1001/CVE-2023-21752
CVE-2023-21752HIGH10 ene 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8
CVE-2021-29447HIGH10 ene 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC
zabbix saml bypass
CVE-2022-23131CRITICALbajo ataque09 ene 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC
G01d3nW01f/CVE-2021-43798
CVE-2021-43798HIGHbajo ataque09 ene 2023
Grafana path traversal
100RIESGO
abrir
GitHub PoC28
CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad
CVE-2023-0297CRITICAL09 ene 2023
Code Injection in pyload/pyload
85RIESGO
abrir
anteriorpágina 285 / 459siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.