Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC4
Exploit for CVE-2020-3952 in vCenter 6.7 https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/
CVE-2020-3952CRITICALbajo ataque19 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
GitHub PoC1
D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1
CVE-2019-1752518 abr 2020
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and
23RIESGO
abrir
GitHub PoC2
VMWare vmdir missing access control exploit checker
CVE-2020-3952CRITICALbajo ataque17 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
GitHub PoC43
CVE-2020-10199 Nexus <= 3.21.1 远程代码执行脚本(有回显)
CVE-2020-10199HIGHbajo ataque16 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
GitHub PoC11
CVE-2020-5260演示记录
CVE-2020-5260CRITICAL16 abr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RIESGO
abrir
GitHub PoC274
Exploit for CVE-2020-3952 in vCenter 6.7
CVE-2020-3952CRITICALbajo ataque16 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
GitHub PoC28
This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.
CVE-2019-11510CRITICALbajo ataqueransomware16 abr 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC6
NVMS 1000 - Directory Traversal Attack Exploit for CVE-2019-20085
CVE-2019-20085HIGHbajo ataque15 abr 2020
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
GitHub PoC37
A HTTP PoC Endpoint for cve-2020-5260 which can be deployed to Heroku
CVE-2020-5260CRITICAL15 abr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RIESGO
abrir
GitHub PoC
https://bugs.chromium.org/p/project-zero/issues/detail?id=2021
CVE-2020-5260CRITICAL15 abr 2020
malicious URLs may cause Git to present stored credentials to the wrong server
53RIESGO
abrir
GitHub PoC4
Vuln Check
CVE-2020-3952CRITICALbajo ataque15 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
GitHub PoC27
patches for SNYK-JS-JQUERY-565129, SNYK-JS-JQUERY-567880, CVE-2020-1102, CVE-2020-11023, includes the patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
CVE-2019-1135814 abr 2020
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir
GitHub PoC
This tool helps scan large subnets for cve-2020-0796 vulnerable systems
CVE-2020-0796CRITICALbajo ataqueransomware14 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC19
Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)
CVE-2018-19320HIGHbajo ataqueransomware13 abr 2020
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir
GitHub PoC
Reproduction of privilege escalation breach CVE-2019-3010
CVE-2019-3010HIGHbajo ataque13 abr 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir
GitHub PoC2
https://bugs.chromium.org/p/project-zero/issues/detail?id=1820
CVE-2019-11707HIGHbajo ataque13 abr 2020
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
GitHub PoC8
CVE-2018-7600【Drupal7】批量扫描工具。
CVE-2018-7600CRITICALbajo ataqueransomware12 abr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
Code execution for CVE-2017-11176
CVE-2017-1117610 abr 2020
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RIESGO
abrir
GitHub PoC
This Repository use to test Apache Killer (cve-2011-3192).
CVE-2011-319209 abr 2020
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RIESGO
abrir
GitHub PoC25
CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.
CVE-2020-10199HIGHbajo ataque08 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
GitHub PoC35
CVE-2020-10199、CVE-2020-10204、CVE-2020-11444
CVE-2020-10199HIGHbajo ataque08 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
GitHub PoC8
CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本
CVE-2018-7600CRITICALbajo ataqueransomware07 abr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC19
CVE-2020-10199 CVE-2020-10204 Python POC
CVE-2020-10199HIGHbajo ataque07 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
GitHub PoC7
CVE-2020-0796 (SMBGhost) LPE
CVE-2020-0796CRITICALbajo ataqueransomware07 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC75
Cobalt Strike AggressorScripts CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware06 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
CVE-2017-10271
CVE-2017-10271HIGHbajo ataqueransomware06 abr 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC2
CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability"
CVE-2020-0688HIGHbajo ataqueransomware05 abr 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC4
XAMPP - CVE-2020-11107
CVE-2020-1110705 abr 2020
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RIESGO
abrir
GitHub PoC6
Laravel-PHP-Unit-RCE (CVE-2018-15133) Auto Exploiter and Shell Uploader
CVE-2018-15133HIGHbajo ataque05 abr 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC
Known security vulnerabilities detected. CVE-2022-21831 Critical severity CVE-2025-24293 Critical severity CVE-2020-8162 High severity CVE-2024-26144 Moderate severity
CVE-2025-24293CRITICAL05 abr 2020
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
48RIESGO
abrir
anteriorpágina 401 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.