Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
13.627 exploits
GitHub PoC
CVE-2017-16921: In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RIESGO
abrir ↗GitHub PoC
A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗GitHub PoC★ 2
A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)
Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution
48RIESGO
abrir ↗GitHub PoC★ 13
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir ↗GitHub PoC★ 2
基于135端口检测目标是否存在CVE-2024-38077漏洞
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 2
Perform With Massive Apache OFBiz Zero-Day Scanner & RCE
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗GitHub PoC
lworld0x00/CVE-2024-38077-notes
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 7
检测RDL服务是否运行,快速排查受影响资产
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 1
Sec-Link/CVE-2024-38077
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 13
远程探测 remote desktop licensing 服务开放情况,用于 CVE-2024-38077 漏洞快速排查
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 3
CVE-2024-38077,本仓库仅用作备份,
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 223
RDL的堆溢出导致的RCE
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 9
SecStarBot/CVE-2024-38077-POC
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 1
psl-b/CVE-2024-38077-check
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 5
it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script automates the process of authorization, payload generation, and execution, allowing for remote command execution on the target device.
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RIESGO
abrir ↗GitHub PoC★ 5
it is script designed to interact with a router by sending a payload to its system tools. The script retrieves the router's configuration from environment variables to ensure security. It includes functions for generating an authorization header, sending a payload, and logging the process.
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by
53RIESGO
abrir ↗GitHub PoC
elliotosama/CVE-2012-2982
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir ↗GitHub PoC
jtoalu/CTF-CVE-2019-9053-GTFOBins
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗GitHub PoC
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
Calibre Remote Code Execution
85RIESGO
abrir ↗GitHub PoC
bolkv/CVE-2024-4320
Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui
60RIESGO
abrir ↗GitHub PoC★ 2
exploit que vulnera Jenkins hecho en Python
ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
48RIESGO
abrir ↗GitHub PoC★ 1
An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗GitHub PoC★ 49
Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2024-41651
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func
48RIESGO
abrir ↗GitHub PoC
VanishedPeople/CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗GitHub PoC
This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack. It provides information on the vulnerable code, recommended fixes, and how to extract and decrypt administrative credentials.
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action
48RIESGO
abrir ↗GitHub PoC★ 6
CVE-2024-32113 Apache OFBIZ Batch Scanning
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir ↗GitHub PoC★ 6
Calibre 远程代码执行(CVE-2024-6782)Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
Calibre Remote Code Execution
85RIESGO
abrir ↗GitHub PoC★ 1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC★ 1
This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.