Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
75.526 exploits
VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗VulnCheck XDB
infoleak
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗VulnCheck XDB
initial-access
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗GitHub PoC
elprogramadorgt/CVE-2025-48384
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗GitHub PoC
G01d3nW01f/cve-2023-27372
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗GitHub PoC★ 10
Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗GitHub PoC
This is my implementation of shellshock exploit
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC★ 4
This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious `CIF` file to the hosted `CIF Analyzer` website on the target running on the Chemistry machine from Hack the Box.
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir ↗GitHub PoC
bharath-cyber-root/sharepoint-toolshell-cve-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 2
Do you really think SharePoint is safe?
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Detection rules for CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
rob0tstxt/POC-CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗GitHub PoC★ 2
Fineken/Jenkins-CVE-2024-23897-Lab
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 11
CVE-2025-6018 Poc and Exploit
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir ↗GitHub PoC★ 1
PoC exploit and vulnerable server demo for CVE-2025-1302 in jsonpath-plus.
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RIESGO
abrir ↗GitHub PoC★ 7
DevBuiHieu/CVE-2025-6558-Proof-Of-Concept
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
71RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RIESGO
abrir ↗VulnCheck XDB
client-side
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
71RIESGO
abrir ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗VulnCheck XDB
infoleak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗GitHub PoC★ 1
WordPress联系表单插件 - 未授权任意文件上传漏洞
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RIESGO
abrir ↗VulnCheck XDB
client-side
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.