Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.008 exploits
GitHub PoC★ 21
JSONPath-plus Remote Code Execution
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RIESGO
abrir ↗GitHub PoC
vivigotnotime/CVE-2023-22515-Exploit-Script
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir ↗GitHub PoC★ 4
numanturle/CVE-2025-25279
Arbitrary file read in Mattermost Boards via import & export board archive
53RIESGO
abrir ↗GitHub PoC★ 1
Copy of the POC for CVE-2023-1545
SQL Injection in nilsteampassnet/teampass
41RIESGO
abrir ↗GitHub PoC★ 3
shishirghimir/CVE-2024-53677-Exploit
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗GitHub PoC
Code to exploit CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗GitHub PoC★ 1
WordPress CVE-2024-10924 Exploit for Really Simple Security plugin
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗VulnCheck XDB
initial-access
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC★ 2
cesarbtakeda/7-Zip-CVE-2025-0411-POC
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir ↗GitHub PoC
WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗GitHub PoC
Example usage: exploit.sh http://site.com
SQL Injection in nilsteampassnet/teampass
41RIESGO
abrir ↗GitHub PoC★ 1
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
Remote code execution in Wazuh server
100RIESGO
abrir ↗GitHub PoC★ 4
CVE-2023-1698 Proof of Concept (PoC)
WAGO: WBM Command Injection in multiple products
85RIESGO
abrir ↗GitHub PoC★ 2
PoC of the vulnerability CVE-2024-23346
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir ↗VulnCheck XDB
initial-access
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir ↗GitHub PoC★ 5
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
Remote code execution in Wazuh server
100RIESGO
abrir ↗Metasploit600
Remote Code Execution Vulnerability in XWiki Platform (CVE-2025-24893)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗GitHub PoC
CVE-2025-24971 exploit
OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop
48RIESGO
abrir ↗GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.