Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8410Nuclei 4231Metasploit 3467✓ solo verificadosrecientespopularesriesgo
13.727 exploits
GitHub PoC
LoaiEsam37/CVE-2023-2982
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir ↗GitHub PoC
Achat 0.150 beta7 - Remote Buffer Overflow Rewrite for python3 for the PNPT course.
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir ↗GitHub PoC
pitufo1721/CVE-2025-55182-GodzillaMemoryShell
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC★ 8
An eBPF program to detect attacks on CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC★ 35
Exploit for CVE-2023-3460. Unauthorized admin access for Ultimate Member plugin < v2.6.7
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir ↗GitHub PoC★ 6
This is a PoC for CVE-2023-27372 which spawns a fully interactive shell.
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗GitHub PoC
This is the Updated Python3 exploit for CVE-2019-9053
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗GitHub PoC★ 2
CVE-2017-7921 EXPLOIT
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗GitHub PoC
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!
Authenticated command injection in SNMP options of a Device
63RIESGO
abrir ↗GitHub PoC★ 4
Wordpress CVE-2023-32243
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir ↗GitHub PoC★ 3
Fix WinVerifyTrust Signature Validation Vulnerability, CVE-2013-3900, QID-378332
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗GitHub PoC★ 13
PoC of Imagemagick's Arbitrary File Read
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir ↗GitHub PoC★ 6
Perform With Massive Openfire Unauthenticated Users
Openfire administration console authentication bypass
100RIESGO
abrir ↗GitHub PoC★ 1
Expoit for CVE-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir ↗GitHub PoC
spip
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗GitHub PoC★ 5
Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC★ 9
WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir ↗GitHub PoC★ 11
Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RIESGO
abrir ↗GitHub PoC★ 4
Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
Hamesawian/CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗GitHub PoC★ 82
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir ↗GitHub PoC
yangshifan-git/CVE-2021-1732
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 21
非常简单的CVE-2023-0386's exp and analysis.Use c and sh.
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗GitHub PoC
ps-interactive/lab_cve-2021-4034-polkit-emulation-and-detection
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗GitHub PoC★ 179
fortra/CVE-2023-28252
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir ↗GitHub PoC★ 13
This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id: CVE-2022-42889.
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗GitHub PoC★ 14
A Python script for generating exploits targeting CVE-2022-4510 RCE Binwalk. It supports SSH, command execution, and reverse shell options. Exploits are saved in PNG format. Ideal for testing and demonstrations.
Path Traversal in binwalk
46RIESGO
abrir ↗GitHub PoC
manavvedawala/CVE-2023-32243-proof-of-concept
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir ↗GitHub PoC
An exploit for the Nibbles manager version 4.0.3. This exploit allows RCE to be performed.
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir ↗GitHub PoC★ 2
Tools for working with ImageMagick to handle arbitrary file read vulnerabilities. Generate, read, and apply profile information to PNG files using a command-line interface.
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.