Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8216Nuclei 4223Metasploit 3464✓ solo verificadosrecientespopularesriesgo
75.589 exploits
Exploit-DB
Sitecore 10.4 - Remote Code Execution (RCE)
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RIESGO
abrir ↗Exploit-DB
Microsoft Excel 2024 Use after free - Remote Code Execution (RCE)
Microsoft Excel Remote Code Execution Vulnerability
41RIESGO
abrir ↗Exploit-DB
Social Warfare WordPress Plugin 3.5.2 - Remote Code Execution (RCE)
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir ↗GitHub PoC★ 5
Script para determinar si Citrix es vulnerable al CVE-2025-6543
Memory overflow vulnerability leading to unintended control flow and Denial of Service
78RIESGO
abrir ↗GitHub PoC★ 7
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RIESGO
abrir ↗Exploit-DB
McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information
Improper Verification of Cryptographic Signature by McAfee Agent
33RIESGO
abrir ↗Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RIESGO
abrir ↗GitHub PoC
Poc - CVE-2025-49132
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RIESGO
abrir ↗GitHub PoC★ 3
ademto/wordpress-cve-2024-10924-pentest
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.9.2 CVE-2025-47577 PoC
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RIESGO
abrir ↗VulnCheck XDB
infoleak
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RIESGO
abrir ↗GitHub PoC
Batch RCE scanner for vulnerable vBulletin instances using replaceAdTemplate exploit.
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RIESGO
abrir ↗GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.8.2 CVE-2024-43917 PoC
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RIESGO
abrir ↗GitHub PoC
C-based PoC for CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir ↗GitHub PoC
hdgokani/CVE-2018-1273
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RIESGO
abrir ↗VulnCheck XDB
infoleak
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗VulnCheck XDB
initial-access
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗VulnCheck XDB
local
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir ↗GitHub PoC
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗GitHub PoC
Exploit para escalada de privilegios en Linux basado en la vulnerabilidad Dirty Cow (CVE-2016-5195). Incluye binario, código fuente e instrucciones para su uso en entornos controlados.
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗GitHub PoC
luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗GitHub PoC
CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RIESGO
abrir ↗GitHub PoC
A script is a PoC for CVE-2022-1257, a vulnerability in the McAfee Agent (Trellix Agent) when working with it's database. The vulnerability allows attackers to retrieve and decrypt credentials from the McAfee Agent database file (`ma.db`) due to improper encryption key handling.
Improper Verification of Cryptographic Signature by McAfee Agent
33RIESGO
abrir ↗GitHub PoC
Rust Macros No Recoil Guide 🚀 Boost Aim Like a Pro in C and Python
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.