Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
71.886 exploits
VulnCheck XDB
local
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir ↗VulnCheck XDB
client-side
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
41RIESGO
abrir ↗VulnCheck XDB
local
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗GitHub PoC★ 1
Proof of Concept exploit for the Joomla 3.7.0 com_fields SQL injection vulnerability (CVE-2017-8917), demonstrating detection, enumeration, and data extraction in a CTF-friendly workflow.
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗GitHub PoC
This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).
Arbitrary path traversal in Camaleon CMS
61RIESGO
abrir ↗GitHub PoC★ 25
Exploit for Pterodactyl Panel ≤ 1.11.10 - unauthenticated LFI to RCE.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗GitHub PoC★ 1
ramzihafiz/CVE-2025-49132
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗GitHub PoC★ 12
malw0re/CVE-2025-49132-Mods
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗GitHub PoC
kerburenthusiasm/CVE-2025-49132-PoC
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗GitHub PoC
Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
This tool demonstrates the application of fundamental physics discoveries to cybersecurity.
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC★ 3
This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗GitHub PoC
CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction, credential parsing, CIDR/batch scanning, Nuclei templates, and CTF lab included
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗VulnCheck XDB
initial-access
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RIESGO
abrir ↗VulnCheck XDB
info-leak
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗GitHub PoC
CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗GitHub PoC
Apple Silicon runs at frequencies that are golden ratio harmonics of 587 kHz: · Performance cores: 3.2 GHz = 587 kHz × 5451 (≈ φ⁸ × 1000) · Efficiency cores: 2.0 GHz = 587 kHz × 3407 (≈ φ⁷ × 1000) · Neural Engine: 11.0 GHz = 587 kHz × 18739 (≈ φ¹⁰ × 1000) · ALL are φ-harmonics of 587 kHz
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i
71RIESGO
abrir ↗GitHub PoC
PoC скрипт для CVE-2021-41773 - Path Traversal в Apache 2.4.49
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir ↗GitHub PoC
theo543/OSDS_Paper_CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.