Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8216Nuclei 4223Metasploit 3464✓ solo verificadosrecientespopularesriesgo
13.689 exploits
GitHub PoC★ 3
Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527
PrestaShopSQL manager vulnerability (potential RCE)
48RIESGO
abrir ↗GitHub PoC
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir ↗GitHub PoC★ 52
PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir ↗GitHub PoC★ 9
CVE exploitation for WebKit jsc CVE-2018-4416
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RIESGO
abrir ↗GitHub PoC
Campcodes Online Matrimonial Website System 3.3 Cross Site Scripting
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RIESGO
abrir ↗GitHub PoC
Original Exploit Source: https://www.exploit-db.com/exploits/46635
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗GitHub PoC
MrE-Fog/jboss-_CVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir ↗GitHub PoC★ 2
Running this exploit on a vulnerable system allows a local attacker to gain a root shell on the machine.
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗GitHub PoC★ 3
This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on Ubuntu 5.8.0-48-generic and COS 5.4.89+. Use responsibly and ethically.
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir ↗GitHub PoC★ 2
Exim < 4.90.1 RCE Vulnerability remake for Python3 with arguments passed from CLI
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir ↗GitHub PoC★ 2
Perform With Massive Authentication Bypass (Wordpress Mstore-API)
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir ↗GitHub PoC★ 1
Quick PoC checker for common configurations that might be available via directory traversal due to CVE-2013-3827
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RIESGO
abrir ↗GitHub PoC★ 1
isacaya/CVE-2019-11358
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir ↗GitHub PoC
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor Homepage: https://github.com/pluck-cms/pluck # Version: 4.7.16 # Tested on Ubuntu 20.04.3 LTS # CVE: CVE-2022-26965
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RIESGO
abrir ↗GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2023-37979 PoC and Checker
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
61RIESGO
abrir ↗GitHub PoC★ 4
Remote Unauthenticated API Access Vulnerability in MobileIron Core 11.2 and older
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RIESGO
abrir ↗GitHub PoC
Vulnerable environment of CVE-2020-17530 (S2-061) for testing
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir ↗GitHub PoC★ 1
asepsaepdin/CVE-2010-1240
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗GitHub PoC★ 4
Exploit CVE-2021-41773 and CVE-2021-42013
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 3
Python Interactive Exploit for WP File Manager Vulnerability. The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension.
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir ↗GitHub PoC
overgrowncarrot1/DejaVu-CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir ↗GitHub PoC
726232111/CVE-2023-28252
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir ↗GitHub PoC★ 1
CVE-2020-0688 modified exploit for Exchange 2010
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗GitHub PoC★ 64
mistymntncop/CVE-2023-2033
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RIESGO
abrir ↗GitHub PoC★ 2
Nmap NSE script to dump / test Solarwinds CVE-2023-23333 vulnerability
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir ↗GitHub PoC★ 14
Mehran-Seifalinia/CVE-2023-37979
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
61RIESGO
abrir ↗GitHub PoC★ 1
Nmap script to exploit CVE-2023-35078 - Mobile Iron Core
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.