Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8410Nuclei 4231Metasploit 3467✓ solo verificadosrecientespopularesriesgo
75.902 exploits
GitHub PoC
This CVE - PoC about information on the CVEs I found.
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
33RIESGO
abrir ↗GitHub PoC★ 1
olimpiofreitas/CVE-2025-29927-scanner
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 3
This repository includes everything needed to run a PoC exploit for CVE-2025-32375 in a Docker environment. It runs the latest vulnerable version of BentoML (1.4.7).
Insecure Deserialization leads to RCE in BentoML's runner server
75RIESGO
abrir ↗GitHub PoC
Vite Development Server's @fs endpoint (CVE-2025-31125) to access sensitive files like /etc/passwd and /etc/hosts via crafted URLs.
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir ↗GitHub PoC
A critical flaw has been discovered in Erlang/OTP's SSH server allows unauthenticated attackers to gain remote code execution. One malformed SSH handshake bypasses authentication and exploits improper handling of SSH protocol messages.
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir ↗GitHub PoC
CVE-2024-10914 Shell Exploit
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗GitHub PoC★ 1
ByteMe1001/CVE-2020-13151-POC-Aerospike-Server-Host-Command-Execution-RCE-
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RIESGO
abrir ↗GitHub PoC★ 1
CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗GitHub PoC
sattarbug/Analysis-of-TomcatKiller---CVE-2025-31650-Exploit-Tool
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RIESGO
abrir ↗GitHub PoC★ 1
CVE-2016-5195 linux kernel exploit
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗GitHub PoC
This python scripts searches a client list to see if their FortiGate device is vulnerable to this CVE.
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir ↗VulnCheck XDB
denial-of-service
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗GitHub PoC
Simple PoC of wpstorecart before 2.5.30 plugin exploit (CVE-2012-3576) written in bash.
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re
28RIESGO
abrir ↗GitHub PoC
katseyres2/CVE-2022-44268-pilgrimage
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir ↗GitHub PoC
toothbrushsoapflannelbiscuits/cve-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
Microsoft - NTLM Hash Disclosure Spoofing (library-ms)
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗GitHub PoC★ 9
CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2024-27956 - WP Automatic SQL Injection Exploit Tool
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir ↗VulnCheck XDB
initial-access
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2025-31650 PoC
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RIESGO
abrir ↗GitHub PoC★ 20
A tool designed to detect the vulnerability **CVE-2025-31650** in Apache Tomcat (versions 10.1.10 to 10.1.39)
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.