Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.447exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8198Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
75.447 exploits
VulnCheck XDB
infoleak
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC
Berisi 2 program C dari exploitDB untuk melakukan privillage eskalation untuk ubuntu 16.04
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗GitHub PoC
Program python untuk melakukan RCE pada drupal versi 7.56
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga
61RIESGO
abrir ↗GitHub PoC★ 1
PoC of CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 1
Esse script explora a vulnerabilidade CVE-2025-20124 — uma falha de Java Deserialization no Cisco ISE (Identity Services Engine) que permite Remote Code Execution (RCE).
Cisco Identity Services Engine Java Deserialization Vulnerability
53RIESGO
abrir ↗GitHub PoC★ 1
00xCanelo/CVE-2024-47533-PoC
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RIESGO
abrir ↗GitHub PoC★ 8
CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated remote code execution via the XMLRPC interface.
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RIESGO
abrir ↗GitHub PoC★ 46
WinRAR 0day CVE-2025-8088 PoC RAR Archive
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗Exploit-DB
Ghost CMS 5.59.1 - Arbitrary File Read
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir ↗Exploit-DB
Ghost CMS 5.42.1 - Path Traversal
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RIESGO
abrir ↗GitHub PoC
These PoC python scripts test the Kemp LoadMaster for remote code execution.
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection
75RIESGO
abrir ↗GitHub PoC★ 3
CVE-2024-47533: Cobbler Authentication Bypass & Code Execution
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RIESGO
abrir ↗Exploit-DB
Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RIESGO
abrir ↗GitHub PoC
Bash POC script for RCE vulnerability in Apache 2.4.49
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗Exploit-DB
JetBrains TeamCity 2023.11.4 - Authentication Bypass
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗Exploit-DB
Citrix NetScaler ADC/Gateway 14.1 - Memory Disclosure
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗Exploit-DB
Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials
Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
48RIESGO
abrir ↗Exploit-DB
atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)
atjiu pybbs list cross site scripting
33RIESGO
abrir ↗Exploit-DB
Cisco ISE 3.0 - Remote Code Execution (RCE)
Cisco Identity Services Engine Java Deserialization Vulnerability
53RIESGO
abrir ↗GitHub PoC★ 4
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗Exploit-DB
VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability
33RIESGO
abrir ↗Exploit-DB
projectworlds Online Admission System 1.0 - SQL Injection
projectworlds Online Admission System adminlogin.php sql injection
33RIESGO
abrir ↗Exploit-DB
Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution (RCE)
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Exploit-DB
ServiceNow Multiple Versions - Input Validation & Template Injection
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir ↗GitHub PoC
Update the old POC of CVE-2025-5777 Citrix NetScaler Memory leak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.