Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.008 exploits
GitHub PoC★ 1
A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injecting entries into /etc/passwd and /etc/shadow. POC
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir ↗GitHub PoC
thunww/CVE-2024-50379
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir ↗GitHub PoC
cyberdesu/Elastix-2.2.0-CVE-2012-4869
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RIESGO
abrir ↗GitHub PoC
CVE-2009-1151, phpMyAdmin의 set.up
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RIESGO
abrir ↗GitHub PoC★ 9
IngressNightmare-PoC: (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) PoC ,One-click script 。 一键脚本
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RIESGO
abrir ↗GitHub PoC★ 1
Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC★ 1
This repository contains a shell script based POC on Apache Tomcat CVE-2025-24813. It allow you to easily test the vulnerability on any version of Apache Tomcat
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC
Next.js Auth Bypass Lab ‐ CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir ↗VulnCheck XDB
initial-access
User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
68RIESGO
abrir ↗GitHub PoC★ 1
Here is a simple but effective exploit for CVE-2025-29927.
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 2
This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC
Next.js CVE-2025-29927 demonstration
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 1
cesarbtakeda/Windows-Explorer-CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗GitHub PoC
Sornphut/CVE-2023-7028-GitLab
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗Exploit-DB
XWiki Standard 14.10 - Remote Code Execution (RCE)
XWiki Admin Tools Application Run Shell Command allows CSRF RCE attacks
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗GitHub PoC
dustblessnotdust/CVE-2024-25180
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf
48RIESGO
abrir ↗VulnCheck XDB
initial-access
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RIESGO
abrir ↗VulnCheck XDB
initial-access
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.