Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8182Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
71.957 exploits
GitHub PoC
dkq-k/cve-2023-22515-1
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗GitHub PoC
A simple Python proof-of-concept tool to check for Apache path traversal vulnerability (CVE-2021-41773). Detects vulnerable server versions and verifies exploitation by probing sensitive files. Built for learning CVE analysis, not mass exploitation.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 1
Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521)
luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗GitHub PoC★ 2
LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Kai-One001/React-Router-CVE-2025-61686-
React Router has Path Traversal in File Session Storage
53RIESGO
abrir ↗GitHub PoC
dkq-k/CVE-2023-22515
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗GitHub PoC
Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a Metasploitable 2 machine with a reverse shell to access the root folder. Once this folder has been accessed, it should reveal the /etc/shadow folder which would give proof of compromise.
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗GitHub PoC
This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known post-exploitation IOCs.
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RIESGO
abrir ↗GitHub PoC
End-to-end remediation of CVE-2013-3900 using PowerShell and Tenable. Demonstrates vulnerability identification, registry hardening, and automated verification in an Azure environment
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗GitHub PoC★ 1
Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-specific attacks (CVE-2022-21449, CVE-2018-0114).
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir ↗GitHub PoC
faisha1311/React2Shell-CVE-2025-55182-TryHackMe
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
A stored Cross‑Site Scripting vulnerability exists in xxl-job-admin JobInfoController.java where the addressList parameter accepts unsanitized URL‑encoded JavaScript. The payload is stored and later executed in users’ browsers, lead unauthorized actions.
Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a cra
33RIESGO
abrir ↗VulnCheck XDB
initial-access
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗GitHub PoC★ 2
WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型的场景下,攻击者可利用此漏洞绕过访问控制、获取敏感数据或实现代码执行。
News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion
48RIESGO
abrir ↗GitHub PoC
🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC
shubtheone/CVE-2021-36260-hikvision
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir ↗GitHub PoC
CVE-2025-61686复现的dockerfile与poc
React Router has Path Traversal in File Session Storage
53RIESGO
abrir ↗GitHub PoC
CVE-2025-11953 - The React Native Metro server's default external binding exposes a vulnerable endpoint, allowing unauthenticated attackers to execute arbitrary OS commands via a malicious POST request.
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir ↗GitHub PoC★ 1
Authorized high-impact tool from CYBERDUDEBIVASH ECOSYSTEM to detect CVE-2025-64155 (FortiSIEM phMonitor Command Injection). Scans for open ports and vulnerable behaviors ethically.
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RIESGO
abrir ↗GitHub PoC★ 2
Phantom Signature Attack: An Analysis of the Critical Vulnerability CVE-2025-29774 in the Bitcoin Protocol, SIGHASH_SINGLE Implementation Flaws, and the Mathematical Framework for Private Key Recovery in Lost Cryptocurrency Wallets Enabling Unrestricted Control over BTC Assets
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
48RIESGO
abrir ↗GitHub PoC
beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗VulnCheck XDB
local
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
encikayelwhitehat-glitch/CVE-2024-3094
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC
🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and efficiently.
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.