Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.842 exploits
GitHub PoC★ 4
Auto exploit for CVE-2025-6018 & CVE-2025-6019 based on https://github.com/0rionCollector/Exploit-Chain-CVE-2025-6018-6019
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir ↗GitHub PoC★ 1
George0Papasotiriou/CVE-2025-8110-Gogs-Remote-Code-Execution
File overwrite in file update API in Gogs
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir ↗GitHub PoC
faysalferdous/CVE-2025-68645-Exploiting-Zimbra-Webmail-LFI-Vulnerability
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RIESGO
abrir ↗GitHub PoC
bananoname/CVE-2024-6386-WPML-SSTI
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
53RIESGO
abrir ↗GitHub PoC
Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2025-54253 | CVE-2025-54254 | Adobe Experience Manager Forms XXE → RCE Framework
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir ↗GitHub PoC★ 1
George0Papasotiriou/CVE-2025-61882-Oracle-BI-Publisher-RCE
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗VulnCheck XDB
client-side
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 1
George0Papasotiriou/CVE-2025-15556-Notepad-WinGUp-Updater-RCE
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
71RIESGO
abrir ↗GitHub PoC★ 1
George0Papasotiriou/CVE-2025-59470-PostgreSQL-Command-Injection
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal
48RIESGO
abrir ↗GitHub PoC★ 3
George0Papasotiriou/CVE-2025-14174-Chrome-Zero-Day
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
63RIESGO
abrir ↗GitHub PoC★ 1
George0Papasotiriou/CVE-2025-55182-React2Shell-CVSS-10.0-
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
RCE on Next 16.0.6
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗GitHub PoC★ 1
An exploitation tool for the Next.js vulnerability CVE-2025-55182 that allows remote command execution through a poisoning prototype in React Server Components.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
Proof-of-concept exploit for CVE-2017-12542, an authentication bypass vulnerability in HP iLO. Allows vulnerability detection and unauthorized account creation on affected systems
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir ↗GitHub PoC★ 1
IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale queries, YARA/Sigma rules, and MITRE ATT&CK mapping.
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
71RIESGO
abrir ↗VulnCheck XDB
initial-access
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗GitHub PoC★ 1
This repo contains RCE exploit for Pterodactyl htb machine
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗VulnCheck XDB
client-side
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC★ 4
Exploit Chain of CVE-2025-6018 to CVE-2025-6019
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir ↗VulnCheck XDB
initial-access
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir ↗GitHub PoC★ 16
A Proof of Concept for chaining CVE-2025-6018 (PAM/Polkit Active Session Bypass) and CVE-2025-6019 (libblockdev SUID Mount Flaw) to achieve Local Privilege Escalation (LPE) on vulnerable Linux systems.
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.