Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.439exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.639VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
81.192 exploits
GitHub PoC
Bash POC script for RCE vulnerability in Apache 2.4.49
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗Exploit-DB
projectworlds Online Admission System 1.0 - SQL Injection
projectworlds Online Admission System adminlogin.php sql injection
33RIESGO
abrir ↗GitHub PoC★ 4
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗Exploit-DB
Cisco ISE 3.0 - Authorization Bypass
Cisco Identity Services Engine Insufficient Authorization Bypass Vulnerability
53RIESGO
abrir ↗Exploit-DB
VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability
33RIESGO
abrir ↗Exploit-DB
Grav CMS 1.7.48 - Remote Code Execution (RCE)
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RIESGO
abrir ↗Exploit-DB
Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RIESGO
abrir ↗Exploit-DB
Ghost CMS 5.42.1 - Path Traversal
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RIESGO
abrir ↗Exploit-DB
JetBrains TeamCity 2023.11.4 - Authentication Bypass
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC
alexander47777/CVE-2016-10033
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Exploit-DB
atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)
atjiu pybbs list cross site scripting
33RIESGO
abrir ↗Exploit-DB
Cisco ISE 3.0 - Remote Code Execution (RCE)
Cisco Identity Services Engine Java Deserialization Vulnerability
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗Exploit-DB
Ghost CMS 5.59.1 - Arbitrary File Read
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir ↗VulnCheck XDB
infoleak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗Exploit-DB
Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials
Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
48RIESGO
abrir ↗GitHub PoC
Update the old POC of CVE-2025-5777 Citrix NetScaler Memory leak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗VulnCheck XDB
client-side
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
76RIESGO
abrir ↗GitHub PoC
BiiTts/POC-IngressNightmare-CVE-2025-1974
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗GitHub PoC★ 10
Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗GitHub PoC
kylew1004/cve-2017-5941-poc-docker-lab
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RIESGO
abrir ↗GitHub PoC★ 6
POC for CVE-2025-4404
Freeipa: idm: privilege escalation from host to domain admin in freeipa
48RIESGO
abrir ↗GitHub PoC★ 4
POC exploit for CVE-2025-24893
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗GitHub PoC
TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC
RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.