Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
14.014 exploits
GitHub PoC
TateYdq/CVE-2018-9995-ModifiedByGwolfs
CVE-2018-999520 abr 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC15
Python script to exploit confluence path traversal vulnerability cve-2019-3398
CVE-2019-3398HIGHbajo ataque20 abr 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RIESGO
abrir
GitHub PoC31
CVE-2019-3799 - Spring Cloud Config Server: Directory Traversal < 2.1.2, 2.0.4, 1.4.6
CVE-2019-379917 abr 2019
Directory Traversal with spring-cloud-config-server
60RIESGO
abrir
GitHub PoC
A python script that tests for an exploitable instance of CVE-2018-1235.
CVE-2018-123517 abr 2019
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RIESGO
abrir
GitHub PoC81
Apache Tomcat Remote Code Execution on Windows - CGI-BIN
CVE-2019-023216 abr 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC190
Apache Tomcat Remote Code Execution on Windows
CVE-2019-023215 abr 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC3
CVE-2018-16858 exploit implementation
CVE-2018-16858HIGH14 abr 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
GitHub PoC1
Exploit for the CVE-2019-5736 runc vulnerability
CVE-2019-573613 abr 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC1
🔍 Explore and test the CVE-2025-49844 (RediShell) vulnerability in Redis with this practical lab environment for secure education and research.
CVE-2025-49844CRITICAL13 abr 2019
Redis Lua Use-After-Free may lead to remote code execution
85RIESGO
abrir
GitHub PoC57
jenkins CVE-2017-1000353 POC
CVE-2017-1000353CRITICALbajo ataque12 abr 2019
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir
GitHub PoC
s1xg0d/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
Confluence Widget Connector RCE - ptquan
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC39
Confluence Widget Connector RCE
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC2
likekabin/CVE-2019-0841
CVE-2019-0841HIGHbajo ataqueransomware10 abr 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
GitHub PoC174
CVE-2019-3396 confluence SSTI RCE
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC145
Confluence 未授权 RCE (CVE-2019-3396) 漏洞
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC50
rogue-kdc/CVE-2019-1253
CVE-2019-1253HIGHbajo ataqueransomware10 abr 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
GitHub PoC
Confluence Widget Connector RCE
CVE-2019-3396CRITICALbajo ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC22
Confluence Widget Connector path traversal (CVE-2019-3396)
CVE-2019-3396CRITICALbajo ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
xiaoshuier/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC239
PoC code for CVE-2019-0841 Privilege Escalation vulnerability
CVE-2019-0841HIGHbajo ataqueransomware05 abr 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
GitHub PoC1
likekabin/CVE-2019-0604_sharepoint_CVE
CVE-2019-0604CRITICALbajo ataqueransomware04 abr 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
GitHub PoC4
ManageEngine Service Desk Plus 10.0 Privilaged account Hijacking
CVE-2019-1000804 abr 2019
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session
28RIESGO
abrir
GitHub PoC
Example and demo setup for Heartbleed vulnerability (CVE-2014-0160). This should be used for testing purposes only!💔
CVE-2014-0160HIGHbajo ataque03 abr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS
CVE-2014-0160HIGHbajo ataque02 abr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC2
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Print Archive System v2015 release 2.6
CVE-2019-1068502 abr 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
23RIESGO
abrir
GitHub PoC3
a demo for Ruby on Rails CVE-2019-5418
CVE-2019-5418HIGHbajo ataque01 abr 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
GitHub PoC4
Just a PoC tool to extract password using CVE-2019-1653.
CVE-2019-1653HIGHbajo ataque01 abr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
GitHub PoC10
eps漏洞(CVE-2017-0261)漏洞分析
CVE-2017-0261HIGHbajo ataque31 mar 2019
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RIESGO
abrir
GitHub PoC36
CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)
CVE-2018-9276HIGHbajo ataque31 mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
anteriorpágina 427 / 468siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.