Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8216Nuclei 4223Metasploit 3464✓ solo verificadosrecientespopularesriesgo
13.689 exploits
GitHub PoC★ 1
NetScaler (Citrix ADC) CVE-2023-3519 Scanner
Unauthenticated remote code execution
100RIESGO
abrir ↗GitHub PoC★ 86
Accurately fingerprint and detect vulnerable (and patched!) versions of Netscaler / Citrix ADC to CVE-2023-3519
Unauthenticated remote code execution
100RIESGO
abrir ↗GitHub PoC
PowerShell Script for initial mitigation of vulnerability
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir ↗GitHub PoC★ 1
lakshit1212/CVE-2021-23017-PoC
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir ↗GitHub PoC★ 4
A PoC exploit for CVE-2010-4231 - Directory Traversal Vulnerability in Camtron and TecVoz IP Cameras.
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera an
43RIESGO
abrir ↗GitHub PoC★ 2
A PoC exploit for CVE-2015-2166 - Directory Traversal Vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP)
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5
43RIESGO
abrir ↗GitHub PoC
Muhammad-Ali007/Log4j_CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
This shellscript given the OrgKey 0 will parse the header of the base64 artifacts found in MOVEit Logs and decrypt the Serialized object used a payload
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗GitHub PoC★ 2
Automating Exploitation of CVE-2022-44268 ImageMagick Arbitrary File Read
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir ↗GitHub PoC★ 2
This script allows for remote code execution (RCE) on Oracle WebLogic Server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗GitHub PoC★ 6
Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints
WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability
63RIESGO
abrir ↗GitHub PoC
d0x-awrqxavc/CVE-2019-7609-KibanaRCE
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗GitHub PoC★ 1
Muhammad-Ali007/Follina_MSDT_CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 15
Script to check for CVE-2023-36884 hardening
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir ↗GitHub PoC
Fuel CMS 1.4.1 - Remote Code Execution - Python 3.x
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗GitHub PoC★ 4
NyaMeeEain/CVE-2022-28171-POC
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
53RIESGO
abrir ↗GitHub PoC★ 2
This is an emergency solution while Microsoft addresses the vulnerability.
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir ↗GitHub PoC★ 22
Muhammad-Ali007/OutlookNTLM_CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2023-33592批量漏洞利用程序
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RIESGO
abrir ↗GitHub PoC★ 46
Apache RocketMQ Arbitrary File Write Vulnerability Exploit
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir ↗GitHub PoC
Pog-Frog/cve-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir ↗GitHub PoC
Proof of concept for LabVIEW Web Server HTTP Get Newline DoS vulnerability
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET reques
28RIESGO
abrir ↗GitHub PoC★ 1
Recent Campaign abusing CVE-2023-36884
Windows Search Remote Code Execution Vulnerability
93RIESGO
abrir ↗GitHub PoC★ 2
This is a Python3 script that demonstrates an exploit for a Blind SQL Injection vulnerability in WebERP version 4.15.
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is d
23RIESGO
abrir ↗GitHub PoC★ 106
Full Chain Analysis of CVE-2022-4262, a non-trivial feedback slot type confusion in V8.
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corru
76RIESGO
abrir ↗GitHub PoC★ 13
This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server. The script supports both Windows and Linux (On testing) platforms, and it can be used to exploit individual targets or perform mass checking on a list of URLs.
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.