Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8410Nuclei 4231Metasploit 3467✓ solo verificadosrecientespopularesriesgo
75.902 exploits
GitHub PoC★ 1
Erlang OTP SSH NSE Discovery Script
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗GitHub PoC
A PoC of CVE-2018-0114 I made for PentesterLab
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir ↗GitHub PoC
K4Der11000/k4_cve-2023-41064
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
76RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir ↗GitHub PoC★ 4
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir ↗GitHub PoC
Python Proof of Concept for CVE-2023-1545 (SQL Injection for Teampass versions prior to 3.0.0.23).
SQL Injection in nilsteampassnet/teampass
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection
70RIESGO
abrir ↗GitHub PoC
CVE lab to accompany CVE course for CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir ↗GitHub PoC★ 12
Exploit for CVE-2025-30406
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir ↗GitHub PoC
unzip-stream file write/overwrite vulnerability
Arbitrary File Write via artifact extraction in actions/artifact
41RIESGO
abrir ↗GitHub PoC
Optimized exploit for CVE-2021-43857 affecting Gerapy < 0.9.8
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir ↗GitHub PoC
Commvault CVE-2025-34028 endpoint scanner using Nmap NSE. For ethical testing and configuration validation.
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir ↗GitHub PoC
JIYUN02/cve-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 1
tar-fs file write/overwrite vulnerability
An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted
41RIESGO
abrir ↗GitHub PoC
Jasurbek-Masimov/CVE-2018-15745
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir ↗GitHub PoC★ 3
Analysis of the Reproduction of CVE-2025-30208 Series Vulnerabilities
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗VulnCheck XDB
initial-access
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir ↗VulnCheck XDB
initial-access
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
CVE-2025-31161 python exploit
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗GitHub PoC★ 1
Official Nuclei template for CVE-2025-31161 (formerly CVE-2025-2825)
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.