Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.008 exploits
VulnCheck XDB
initial-access
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗Exploit-DB
Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
Remote code Execution inTimeProvider® 4100
46RIESGO
abrir ↗Metasploit600
BentoML RCE
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RIESGO
abrir ↗GitHub PoC★ 12
PoC
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir ↗GitHub PoC
CVE-2021-38163 - SAP NetWeaver AS Java Desynchronization Vulnerability
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RIESGO
abrir ↗GitHub PoC★ 7
This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It abuses the getDefaultValue() mechanism to instantiate arbitrary record types during parsing, enabling code execution when untrusted data is processed without proper controls.
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir ↗GitHub PoC
WordPress RomethemeKit For Elementor Plugin <= 1.5.4 is vulnerable to Remote Code Execution (RCE)
WordPress RomethemeKit For Elementor plugin <= 1.5.4 - Arbitrary Plugin Installation/Activation to RCE vulnerability
48RIESGO
abrir ↗GitHub PoC
Jenkins CLI arbitrary read (CVE-2024-23897 applies to versions below 2.442 and LTS 2.426.3)
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗Exploit-DB
Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RIESGO
abrir ↗Exploit-DB
Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)
XSS vulnerability in bannerconfig endpoint in TimeProvider 4100
41RIESGO
abrir ↗GitHub PoC★ 1
YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
Path Traversal allowing arbitrary read of files in Yeswiki
56RIESGO
abrir ↗GitHub PoC
Subrion File Upload Bypass to RCE and Custom File Upload (Authenticated) POC
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir ↗GitHub PoC
PoC for CVE-2024-25600
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗Exploit-DB
Vite 6.2.2 - Arbitrary File Read
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗Exploit-DB
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
Hard coded default credential contained in install package
41RIESGO
abrir ↗GitHub PoC★ 7
CVE-2025-30208 - Vite Arbitrary File Read PoC
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC
Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗Exploit-DB
Webmin Usermin 2.100 - Username Enumeration
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RIESGO
abrir ↗Metasploit600
Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir ↗GitHub PoC
Mongo Vulnub Lab...Try to Hack IT.....!
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir ↗Metasploit500
Ivanti Connect Secure Unauthenticated Remote Code Execution via Stack-based Buffer Overflow
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir ↗Metasploit600
pgAdmin Query Tool authenticated RCE (CVE-2025-2945)
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir ↗Exploit-DB
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
Microsoft Office Spoofing Vulnerability
38RIESGO
abrir ↗Metasploit300
Gladinet CentreStack/Triofox Path Traversal
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.