Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
13.654 exploits
GitHub PoC
A basic script that exploits CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC
CVE-2023-0386 包含所需运行库
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗GitHub PoC
CVE-2022-24716 (Arbitrary File Disclosure Icingaweb2)
Path traversal in Icinga Web 2
78RIESGO
abrir ↗GitHub PoC★ 1
A final project for "Network Security" class at NYCU (National Yang Ming Chiao Tung University, Taiwan). Exploiting a CVE in "EasyAppointments" software.
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RIESGO
abrir ↗GitHub PoC★ 216
Oracle VirtualBox Elevation of Privilege (Local Privilege Escalation) Vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RIESGO
abrir ↗GitHub PoC★ 6
A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir ↗GitHub PoC★ 36
CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC
SOPlanning 1.52.00 CSRF/SQLi/XSS (CVE-2024-33722, CVE-2024-33724)
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
33RIESGO
abrir ↗GitHub PoC
TYuan0816/cve-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir ↗GitHub PoC
PoC for CVE-2024-24576 vulnerability "BatBadBut"
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 2
JetBrains TeamCity Unauthenticated Remote Code Execution - Python3 Implementation
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗GitHub PoC
Python exploit and checker script for CVE-2024-3400 Palo Alto Command Injection and Arbitrary File Creation
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC★ 2
Python POC for CVE-2023-6019 taken from https://huntr.com/bounties/d0290f3c-b302-4161-89f2-c13bb28b4cfe
Ray Command Injection in cpu_profile Parameter
85RIESGO
abrir ↗GitHub PoC
bde574786/Sequelize-1day-CVE-2023-25813
SQL Injection via replacements in sequelize
48RIESGO
abrir ↗GitHub PoC★ 1
WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗GitHub PoC
asdfjkl11/CVE-2024-32238
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RIESGO
abrir ↗GitHub PoC
Gaurav1020/CVE-2024-24576-PoC-Rust
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 1
H3C ER8300G2-X config download
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RIESGO
abrir ↗GitHub PoC
Finding Palo Alto devices vulnerable to CVE-2024-3400.
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
ASG-CASTLE/CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗GitHub PoC★ 2
Proof of concept for CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC
ASG-CASTLE/CVE-2023-27350
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗GitHub PoC★ 2
Extract useful information from PANOS support file for CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
Script that exploits the vulnerability that allows remote code execution in Ruby 2.3.8 with CVE-2016-2098
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir ↗GitHub PoC
CVE-2024-3400 POC written in Rust and Python
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
Script that exploits the vulnerability that allows establishing a backdoor in the UnrealIRCd service with CVE-2010-2075
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir ↗GitHub PoC
sxyrxyy/CVE-2024-3400-Check
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
Simple Python code to check for arbitrary uploading for PaloAlto CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
Script that exploits the vulnerability of the ProFTPd 1.3.5 service with CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.