Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
75.445 exploits
VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 1
This is a rewritten exploit to work with php
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3-2-0
Remote Code Execution in Apache Dolphinscheduler
48RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Path Traversal Vulnerability
41RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Argument Injection Vulnerability in CommServe
33RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Unauthorized API Access Risk
28RIESGO
abrir ↗Exploit-DB
RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec
48RIESGO
abrir ↗GitHub PoC★ 3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RIESGO
abrir ↗GitHub PoC
chan-068/CVE-2024-0520_try
Remote Code Execution due to Full Controlled File Write in mlflow/mlflow
48RIESGO
abrir ↗VulnCheck XDB
infoleak
Epsilon Framework Themes (Various Versions) - Function Injection
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗Exploit-DB
PHPMyAdmin 3.0 - Bruteforce Login Bypass
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allo
23RIESGO
abrir ↗Exploit-DB
BigAnt Office Messenger 5.6.06 - SQL Injection
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RIESGO
abrir ↗Exploit-DB
Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)
Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
41RIESGO
abrir ↗GitHub PoC★ 1
The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python interpreter.
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗GitHub PoC
CVE-2015-6967 PoC Exploit
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir ↗GitHub PoC
CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗Exploit-DB
Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗VulnCheck XDB
initial-access
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir ↗GitHub PoC★ 1
harutomo-jp/CVE-2024-28397-RCE
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗GitHub PoC★ 2
Proof of concept for CVE-2020-36708
Epsilon Framework Themes (Various Versions) - Function Injection
75RIESGO
abrir ↗GitHub PoC★ 3
This is an improved version of the CVE-2025-49132 proof of concept exploit.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir ↗GitHub PoC
shoucheng3/keycloak__keycloak_CVE-2022-3782_20-0-1
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs
48RIESGO
abrir ↗Exploit-DB
Tenda AC20 16.03.08.12 - Command Injection
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RIESGO
abrir ↗GitHub PoC★ 1
Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RIESGO
abrir ↗GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir ↗GitHub PoC★ 3
PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.