Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
13.654 exploits
GitHub PoC★ 1
Python script for CMS Made Simple 2.1.6 - Remote Code Execution.
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
28RIESGO
abrir ↗GitHub PoC
CVE-2024-21413 Setup for CW
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
MAL-004: Command Injection Bypass for CVE-2020-12641 in Roundcube Webmail
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RIESGO
abrir ↗GitHub PoC
CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML atta
85RIESGO
abrir ↗GitHub PoC★ 335
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir ↗GitHub PoC
FoxyProxys/CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y 5.6.1 de la herramienta de compresión XZ.
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC★ 2
CerTusHack/CVE-2024-3400-PoC
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC★ 2
PoC MinIO vulnerability exploit
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗GitHub PoC★ 71
CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC★ 11
Yuvvi01/CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC★ 5
OpenMetadata_RCE (CVE-2024-28255) Batch scan/exploit
Authentication Bypass in OpenMetadata
85RIESGO
abrir ↗GitHub PoC★ 2
adhikara13/CVE-2024-2389
Flowmon Unauthenticated Command Injection Vulnerability
85RIESGO
abrir ↗GitHub PoC★ 1
Public exploit for CVE-2024-31777
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RIESGO
abrir ↗GitHub PoC★ 50
CVE-2023-6319 proof of concept
Command injection in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service
48RIESGO
abrir ↗GitHub PoC★ 1
CVE-2024-24576 PoC for Nim Lang
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 2
0xWhoami35/CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
Ray OS Command Injection RCE(Unauthorized)
Ray Command Injection in cpu_profile Parameter
85RIESGO
abrir ↗GitHub PoC★ 5
D-Link NAS Command Execution Exploit
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC★ 20
CVE-2024-24576 Proof of Concept
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 9
brains93/CVE-2024-24576-PoC-Python
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 1
The script is from https://github.com/JohnHammond/msdt-follina, just make it simple for me to use it and this script aim at generating the payload for more information refer the johnn hammond link
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 5
A PoC exploit for CVE-2024-3273 - D-Link Remote Code Execution RCE
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC★ 59
Example of CVE-2024-24576 use case.
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 23
CVE-2024-2879 - LayerSlider 7.9.11 - 7.10.0 - Unauthenticated SQL Injection
The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1
68RIESGO
abrir ↗GitHub PoC
CVE-2020-12641: Command Injection via “_im_convert_path” Parameter in Roundcube Webmail
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RIESGO
abrir ↗GitHub PoC★ 13
Exploit for CVE-2024-3273, supports single and multiple hosts
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC
Quick and dirty honeypot for CVE-2024-3273
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.