Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
13.627 exploits
GitHub PoC★ 1
PoC code for vulnerability in webmod v0.48. Originally written in 2007, assigned CVE-2007-1260.
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RIESGO
abrir ↗GitHub PoC★ 4
Server-Side Template Injection Exploit
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RIESGO
abrir ↗GitHub PoC★ 54
Pre-Auth Exploit for CVE-2024-40711
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RIESGO
abrir ↗GitHub PoC★ 5
A Bash script for Kali Linux that exploits an iOS WebKit vulnerability (CVE-2020-27950) using Metasploit and ngrok. Automates payload delivery with a public URL via ngrok, checks for required tools, handles errors, and provides an easy way to crash browsers for educational purposes only.
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir ↗GitHub PoC★ 1
Unauthenticated remote code execution via Calibre’s content server in Calibre <= 7.14.0.
Calibre Remote Code Execution
85RIESGO
abrir ↗GitHub PoC★ 2
dogucyber/WordPress-Exploit-CVE-2024-1071
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗GitHub PoC★ 48
POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir ↗GitHub PoC
New exploit for pyLoad v0.5.0 - Unauthenticated remote code excecution
Code Injection in pyload/pyload
85RIESGO
abrir ↗GitHub PoC★ 19
Exploit for CVE-2024-29847
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows
60RIESGO
abrir ↗GitHub PoC★ 2
chsxthwik/CVE-2024-2876
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir ↗GitHub PoC★ 2
Robocopsita/CVE-2022-0944_RCE_POC
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir ↗GitHub PoC
🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker successfully bypassed authentication, gaining admin control over the device! Immediate containment was critical. Stay vigilant! 💻🔐
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗GitHub PoC★ 3
Proof-of-Concept Exploit for CVE-2024-36401 GeoServer 2.25.1
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗GitHub PoC
0xWhoami35/CVE-2024-4879
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir ↗GitHub PoC
acidburn2049/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC
sshipanoo/CVE-2024-44542
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.
48RIESGO
abrir ↗GitHub PoC
CVE-2024-8277 - 0Day Auto Exploit Authentication Bypass in WooCommerce Photo Reviews Plugin
WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation
48RIESGO
abrir ↗GitHub PoC
pwning netconsd
netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could
48RIESGO
abrir ↗GitHub PoC
Event ID 189 Rule Name SOC227 Microsoft SharePoint Server Elevation of Privilege Possible CVE-2023-29357 .. Exploitation
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC
Old weaponized CVE-2022-1388 exploit.
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗GitHub PoC
Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)
Authentication bypass using an alternate path or channel
100RIESGO
abrir ↗GitHub PoC
🚨 New Incident Report Completed! 🚨 Just wrapped up "Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)" on LetsDefend.io. This analysis involved investigating an attempted Command Injection targeting our PHP server. Staying ahead of these threats with continuous monitoring and swift containment! 🛡️
Argument Injection in PHP-CGI
100RIESGO
abrir ↗GitHub PoC
My proof of concept for CVE-2019 Microsoft-Edge
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir ↗GitHub PoC★ 2
Spring Cloud Remote Code Execution
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RIESGO
abrir ↗GitHub PoC★ 1
Powershell script that checks for cert padding in the Windows Registry and adds it if it does not exist. Meant to resolve the WinTrustVerify Vulnerability.
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗GitHub PoC
OtisSymbos/CVE-2021-44228-Log4Shell-
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
Log4J exploit CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.