Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.805exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.428VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.805 exploits
Metasploit600
MajorDoMo Console Eval Unauthenticated RCE
MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval
63RIESGO
abrir ↗Metasploit500
GrandStream GXP1600 Unauthenticated Remote Code Execution
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
75RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir ↗GitHub PoC
ross-ns/WSUS-CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir ↗GitHub PoC
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗GitHub PoC
andres101c/Shellshock-CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
Interactive shell client for React Server Components RCE exploitation via __proto__ pollution (CVE-2025-55182)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
PoC and explanation for CVE-2025-4517 used in a CTF I was playing.
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir ↗GitHub PoC
New CVE-2019-7609 which works with python 13
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2025-47812 POC
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗GitHub PoC
rogerzeferino/Apache-Solr-RCE-CVE-2019-17558
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir ↗GitHub PoC★ 1
rogerzeferino/cve-2019-17558-apache-solr-rce
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir ↗GitHub PoC★ 4
CVE For Pterodactyl (For Study and Education)
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗GitHub PoC
Authenticated RCE in Netgate pfSense CE 2.7.2 and 2.8.0
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob
48RIESGO
abrir ↗GitHub PoC
A high-performance Python toolkit to automate the CVE-2025-4517 PATH_MAX bypass exploit. Specifically tuned for the WingData HTB challenge to achieve arbitrary file writes and root persistence
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir ↗GitHub PoC
rootdirective-sec/CVE-2026-23744-Lab
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir ↗GitHub PoC★ 2
CVE‑2025‑4517 Proof‑of‑Concept Script
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗GitHub PoC★ 8
Privilege Escalation script for CVE-2025-4517
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir ↗GitHub PoC★ 8
Python tarfile data filter bypass via PATH_MAX overflow in os.path.realpath() - CVE-2025-4517 / CVE-2025-4330
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir ↗GitHub PoC★ 2
CVE-2025-4517 (CVSS 9.4 – Critical) A vulnerability in Python's `tarfile`
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir ↗GitHub PoC
[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.