Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
13.334 exploits
GitHub PoC
Alienfader/CVE-2020-29607
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir ↗GitHub PoC★ 1
yenyangmjaze/cve-2024-10914
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗GitHub PoC★ 2
demonstriert, wie mittels missbräuchlicher Nutzung eines Swap-Cookies eine VPN-Session übernommen werden kann. Wichtig: Dieses Projekt dient ausschliesslich zu Bildungs- und Forschungszwecken – bitte nur in Umgebungen verwenden, in denen Du explizit authorisiert bist.
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir ↗GitHub PoC
Yami0x777/Belsen_Group-et-exploitation-de-la-CVE-2022-40684
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir ↗GitHub PoC★ 1
cve-2019-5420 POC simple ruby script
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir ↗GitHub PoC
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir ↗GitHub PoC
skrkcb2/CVE-2024-5452
RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
53RIESGO
abrir ↗GitHub PoC★ 1
SSHEnum es una herramienta de enumeración de usuarios SSH basada en CVE-2018-15473. Permite detectar usuarios válidos aprovechando respuestas diferenciadas del servidor. Es rápida, compatible con Python 3.12 y soporta wordlists. Uso exclusivo para auditoría y pruebas de seguridad autorizadas.
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗GitHub PoC
0x7556/CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir ↗GitHub PoC
RogelioPumajulca/CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC
pz-frontend-manager < 1.0.6 - CSRF Profile Picture Exploit
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RIESGO
abrir ↗GitHub PoC
This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege escalation on Ubuntu 20.04 with sudo version 1.8.31 and glibc version 2.31. It includes an assembly-based exploit, a shared object payload, and a Makefile for automated compilation.
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC★ 4
Cityworks deserialization of untrusted data vulnerability Detection
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to
83RIESGO
abrir ↗GitHub PoC★ 3
Snizi/Moodle-CVE-2024-43425-Exploit
Moodle: remote code execution via calculated question types
78RIESGO
abrir ↗GitHub PoC
PoC of CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Directory Traversal Exploit written in Bash for NVMS-1000 (CVE-2019-20085).
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir ↗GitHub PoC★ 1
This is a Python script that exploits the CVE-2024-6624 vulnerability in the JSON API User <= 3.9.3 plugin for WordPress.
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RIESGO
abrir ↗GitHub PoC★ 4
Python script for CVE-2024-0012 / CVE-2024-9474 exploit
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir ↗GitHub PoC
KGorbakon/CVE-2023-41425
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗GitHub PoC
cy3erdr4g0n/CVE-2024-10924
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC★ 1
SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]
Information disclosure
100RIESGO
abrir ↗GitHub PoC★ 1
qw3rtyou/CVE-2021-44228_dockernize
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 4
CVE-2019-2215 poc for Huawei hardened kernel
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir ↗GitHub PoC
In this challenge, I analyzed the Spring4Shell (CVE-2022-22965) vulnerability, investigated security bypasses, and wrote an Incident Postmortem Report detailing the detection, impact, and resolution of the attack. I also implemented a firewall rule in Python to block malicious requests and prevent future exploitation.
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗GitHub PoC★ 1
This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗GitHub PoC
Code to decrypt Huawei passwords CVE-2012-4960
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605
23RIESGO
abrir ↗GitHub PoC
CVE-2017-8869 - MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir ↗GitHub PoC
This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in Academy for Module "Attacking Commoon Applications" and section "Attacking Drupal".
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.