Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
72.018 exploits
VulnCheck XDB
local
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗VulnCheck XDB
initial-access
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
60RIESGO
abrir ↗VulnCheck XDB
initial-access
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir ↗GitHub PoC
0xDTC/XWiki-Platform-RCE-CVE-2025-24893
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗Exploit-DB
MobileDetect 2.8.31 - Cross-Site Scripting (XSS)
MobileDetect Example session_example.php initLayoutType cross site scripting
28RIESGO
abrir ↗Exploit-DB
RosarioSIS 6.7.2 - Cross Site Scripting (XSS)
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php scrip
23RIESGO
abrir ↗Exploit-DB
MaNGOSWebV4 4.0.6 - Reflected XSS
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
38RIESGO
abrir ↗Exploit-DB
openSIS Community Edition 8.0 - SQL Injection
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
23RIESGO
abrir ↗Exploit-DB
RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php sc
38RIESGO
abrir ↗Exploit-DB
PluckCMS 4.7.10 - Unrestricted File Upload
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_resto
41RIESGO
abrir ↗Exploit-DB
phpIPAM 1.4 - SQL-Injection
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
23RIESGO
abrir ↗Exploit-DB
phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
56RIESGO
abrir ↗Metasploit600
WordPress ACF Extended Unauthenticated RCE via prepare_form()
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RIESGO
abrir ↗GitHub PoC
sudlit/CVE-2017-7494
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗Exploit-DB
Piwigo 13.6.0 - SQL Injection
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
48RIESGO
abrir ↗GitHub PoC★ 1
PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗Exploit-DB
phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
33RIESGO
abrir ↗VulnCheck XDB
local
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir ↗Exploit-DB
YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) in yourls/yourls
28RIESGO
abrir ↗Exploit-DB
phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
41RIESGO
abrir ↗VulnCheck XDB
client-side
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RIESGO
abrir ↗VulnCheck XDB
initial-access
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗VulnCheck XDB
initial-access
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir ↗GitHub PoC
boro03/CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗GitHub PoC★ 1
Jorge2Rubio/CVE-2019-0232
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir ↗GitHub PoC
This repo contain a PoC I have done when blind analysis the dbutil_2_3.sys driver for vulnerability. This was created by personal analysis without looking at writeups or even know which CVE exist in this driver. All the knowledge I have is that this driver is vulnerable in some way.
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.