Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.646 exploits
GitHub PoC
Authenticated RCE for Webmin 1.9.0
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow
43RIESGO
abrir ↗GitHub PoC★ 24
CVE-2025-68428 Proof of Concept
jsPDF has Local File Inclusion/Path Traversal vulnerability
48RIESGO
abrir ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC
alxsourin/Helpdesk-Telecom-CVE-2025-64459
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir ↗GitHub PoC★ 1
flame-11/CVE-2025-54068-livewire
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir ↗GitHub PoC
Auto exploitation tool for CVE-2024-24401
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payl
60RIESGO
abrir ↗GitHub PoC
CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 31
CVE-2025-55182-bypass-waf
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC★ 1
Full automation check for CVE-2025-14847 MonogBleed- Finds origin IP and tests for exploit.
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 22
CVE-2025-60188 Atarim Plugin Exploit
WordPress Atarim plugin <= 4.2.1 - Sensitive Data Exposure vulnerability
56RIESGO
abrir ↗GitHub PoC
analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir ↗VulnCheck XDB
initial-access
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir ↗GitHub PoC★ 1
CVE-2022-0847(Linux 内核本地提权漏洞)
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC★ 1
在python3中运行的脚本
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC
analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir ↗GitHub PoC
CVE-2025-55182-poc-json
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC
ingress-nginx admission controller RCE escalation PoC
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC★ 1
Mass Exploit for CVE-2025-29306
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir ↗GitHub PoC
"Once upon a time, the Castle of Reactland trusted all Flight messages... until The Imposter arrived." A storytelling CVE-2025-55182 (React2Shell) demo - Medieval-themed vulnerable React Server Components app for security education.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
initial-access
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2025-14847 MongoDB Memory Leak Exploit
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC
CVE-2025-55182, also known as React2Shell, is a critical vulnerability affecting Next.js applications using React Server Components (RSC) and Server Actions.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.