Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
13.334 exploits
GitHub PoC
This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗GitHub PoC
HFS 2.3m SERVER RCE Vulnerability exploit
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir ↗GitHub PoC
GazettEl/CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir ↗GitHub PoC
This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL injection to extract the username, email, and password hash from the database. Additionally, it supports password cracking using a wordlist.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗GitHub PoC★ 2
Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload
Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload
48RIESGO
abrir ↗GitHub PoC
x3m1Sec/CVE-2019-0232_tomcat_cgi_exploit
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir ↗GitHub PoC
Sornphut/OverlayFS---CVE-2021-3493
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir ↗GitHub PoC
PoC exploit for CVE-2012-2982 (Webmin RCE), for educational purposes.
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir ↗GitHub PoC
Exploitation for CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 2
Combining CVE-2024-8963 & CVE-2024-8190 - For Unauthenticated RCE on Ivanti CSA 4.6 and below
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RIESGO
abrir ↗GitHub PoC★ 1
build-script for CVE-2024-46507 and CVE-2024-46508
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor
56RIESGO
abrir ↗GitHub PoC
GazettEl/CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗GitHub PoC★ 3
Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RIESGO
abrir ↗GitHub PoC
Project on CVE-2022-30190 exploitation and mitigation strategies
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 1
overgrowncarrot1/CVE-2019-1003030
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir ↗GitHub PoC
CVE-2019-18935: Remote Code Execution
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir ↗GitHub PoC★ 129
Deterministic kernel exploit based on CVE-2023-32434.
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RIESGO
abrir ↗GitHub PoC★ 4
Mautic < 5.2.3 Authenticated RCE
Remote Code Execution & File Deletion in Asset Uploads
48RIESGO
abrir ↗GitHub PoC★ 234
POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir ↗GitHub PoC★ 1
skrkcb2/CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗GitHub PoC
cojoben/CVE-2018-13382
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RIESGO
abrir ↗GitHub PoC
monjheta/CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗GitHub PoC
Automation script to exploit the Shellshock vulnerability.
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC★ 7
CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
46RIESGO
abrir ↗GitHub PoC★ 6
CVE-2025-26263 - GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RIESGO
abrir ↗GitHub PoC★ 3
WP Load Gallery <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
WordPress WP Load Gallery Plugin <= 2.1.6 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗GitHub PoC
A Rust exploit for CVE-2024-23346 that functions as a "terminal" (tested on chemistry.htb)
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir ↗GitHub PoC★ 10
XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.