Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
13.812 exploits
GitHub PoC
ernestak/CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2022-30525 POC
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir ↗GitHub PoC★ 2
An Unofficial Patch Follina CVE-2022-30190 (patch) by micrisoft Guidelines.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 4
CVE-2022-26134 - Pre-Auth Remote Code Execution via OGNL Injection
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗GitHub PoC
CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 106
PoC for CVE-2022-26809, analisys and considerations are shown in the github.io.
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC
ahmetfurkans/CVE-2022-22718
Windows Print Spooler Elevation of Privilege Vulnerability
76RIESGO
abrir ↗GitHub PoC★ 2
seymanurmutlu/CVE-2022-24086-CVE-2022-24087
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir ↗GitHub PoC★ 1
A OS Command Injection Vulnerability in the CGI Program of Zyxel
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir ↗GitHub PoC
These are the source codes of the Python scripts to apply the temporary protection against the CVE-2022-30190 vulnerability (Follina)
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Log4Shell CVE-2021-44228 Demo
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
These are two Python scripts compiled to easily and quickly apply temporary protection against the CVE-2022-30190 vulnerability (Follina)
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Practising technical writing with researching CVE-2022-22954 VMware Workspace ONE Access RCE vulnerability.
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗GitHub PoC★ 3
To determine if an APK is vulnerable to CVE-2017-13156
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir ↗GitHub PoC★ 3
NEW EXPLOIT FOR TP LINK
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RIESGO
abrir ↗GitHub PoC
Mitigation for CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 7
PoC for Sourcegraph Gitserver < 3.37.0 RCE (CVE-2022-23642)
Code Injection in Sourcegraph
78RIESGO
abrir ↗GitHub PoC
this is my simple article about CVE 2022-30190 (Follina) analysis. I use the lab from Letsdefend.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 2
proof of concept to CVE-2022-30190 (follina)
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 3
[CVE-2022-26134] Attlasian Confluence RCE
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗GitHub PoC
CVE-2022-26134, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. This is CVE-2022-26134 expoitation script
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗GitHub PoC★ 1
Repository containing the compromised certificate seen in recent CVE-2022-30190 (Follina) attacks.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 3
Bash poc for CVE-2022-1609 WordPress Weblizar Backdoor
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir ↗GitHub PoC★ 33
Exploit Microsoft Zero-Day Vulnerability Follina (CVE-2022-30190)
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution)
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC
Bash poc for CVE-2022-1609 WordPress Weblizar Backdoor
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir ↗GitHub PoC★ 3
CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗GitHub PoC
Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution)
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC
Exploit modificado para el tito Eu
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.