Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
13.627 exploits
GitHub PoC★ 5
PoC of CVE-2024-37759
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerabi
48RIESGO
abrir ↗GitHub PoC
PoC and Bulk Scanner for CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir ↗GitHub PoC★ 6
This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053).
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗GitHub PoC★ 1
rdoix/cve-2024-21762-checker
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir ↗GitHub PoC★ 10
NanoWraith/CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir ↗GitHub PoC★ 1
WanLiChangChengWanLiChang/CVE-2024-29972
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RIESGO
abrir ↗GitHub PoC★ 4
CVE-2024-29275.yaml
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code an
48RIESGO
abrir ↗GitHub PoC
CVE-2023-2825 exploit script
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir ↗GitHub PoC★ 3
This is a Python 3 version of this exploit. Hope it works!!!
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗GitHub PoC★ 72
CVE-2024-28397: js2py sandbox escape, bypass pyimport restriction.
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗GitHub PoC★ 6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗GitHub PoC★ 10
POC for CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir ↗GitHub PoC★ 6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir ↗GitHub PoC★ 3
momika233/CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir ↗GitHub PoC
CVE-2022-22947 exploit script
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir ↗GitHub PoC★ 1
A small tool to create a PoC for CVE-2000-0649.
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RIESGO
abrir ↗GitHub PoC
jakabakos/CVE-2024-4577-PHP-CGI-argument-injection-RCE
Argument Injection in PHP-CGI
100RIESGO
abrir ↗GitHub PoC
This script is the Proof of Concept (PoC) of the CVE-2024-21413, a significant security vulnerability discovered in the Microsoft Windows Outlook having a strong 9.8 critical CVSS score. Named as #MonikerLink Bug, this vulnerability allows the attacker to execute the arbitrary code remotely on the victim's machine, thus becomes a full-fledged RCE.
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 13
CVE-2024-23692 Exploit
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir ↗GitHub PoC★ 1
Ivanti EPM SQL Injection Remote Code Execution Vulnerability(Optimized version based on h3)
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RIESGO
abrir ↗GitHub PoC
Redfox-Security/Digisol-DG-GR1321-s-Password-Policy-Bypass-CVE-2024-2257
Password Policy Bypass Vulnerability in Digisol Router
48RIESGO
abrir ↗GitHub PoC★ 10
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir ↗GitHub PoC
WinRAR漏洞测试复现。详参:https://flowus.cn/share/a3b35db0-ab5e-4abc-b8d3-5ff284e82e7b
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗GitHub PoC
Expolit for CVE-2024-23334 (aiohttp >= 1.0.5> && <=3.9.1)
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir ↗GitHub PoC★ 19
PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in
48RIESGO
abrir ↗GitHub PoC
The TL;DR for the learnings of Windows Vulnerability CVE-2023-28252
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.