Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.505exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.648VulnCheck XDB 8198Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
13.648 exploits
GitHub PoC
CVE-2017-8917 SQL injection Vulnerability in Joomla! 3.7.0 exploit
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗GitHub PoC★ 1
muhammad1596/CVE-2022-0847-dirty-pipe-checker
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC★ 2
Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RIESGO
abrir ↗GitHub PoC★ 5
An Vulnerability detection and Exploitation tool for CVE-2024-4358
Registration Authentication Bypass Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 19
Apache HugeGraph Server Unauthenticated RCE - CVE-2024-27348 Proof of concept Exploit
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir ↗GitHub PoC★ 79
Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)
Registration Authentication Bypass Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 27
Apache OFBIZ Path traversal leading to RCE POC[CVE-2024-32113 & CVE-2024-36104]
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir ↗GitHub PoC★ 3
Sonatype Nexus Repository Manager 3 (LFI)
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗GitHub PoC★ 2
kevcooper/CVE-2024-1086-checker
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir ↗GitHub PoC★ 1
CVE-2023-51518: Preauthenticated Java Deserialization via JMX in Apache James
Apache James server: Privilege escalation via JMX pre-authentication deserialisation
48RIESGO
abrir ↗GitHub PoC★ 4
Nmap script to check vulnerability CVE-2024-24919
Information disclosure
100RIESGO
abrir ↗GitHub PoC
Exploit created by nu11secur1ty (https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2022-37706)
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir ↗GitHub PoC★ 1
New exploit for Apache APISIX v2.12.1 - Remote code execution (RCE)
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.
Information disclosure
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2024-24919 Sniper - A powerful tool for scanning Check Point Security Gateway CVE-2024-24919 vulnerability. Supports single & bulk scanning, multithreading, and generates detailed CSV reports. Ideal for penetration testers and security researchers.
Information disclosure
100RIESGO
abrir ↗GitHub PoC
CVE-2021-41773.py
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 1
adyanamul/Remote-Code-Execution-RCE-Exploit-BlueKeep-CVE-2019-0708-PoC
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir ↗GitHub PoC★ 1
phpMyAdmin <4.9.0 - Cross-Site Request Forgery
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF
28RIESGO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2019-7609 in python
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.