Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.053exploits catalogados
34.675CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.758VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.054 exploits
VulnCheck XDB
client-side
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir ↗GitHub PoC★ 1
yenyangmjaze/cve-2024-10914
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗GitHub PoC
Alienfader/CVE-2020-29607
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗GitHub PoC
Yami0x777/Belsen_Group-et-exploitation-de-la-CVE-2022-40684
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗GitHub PoC
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir ↗GitHub PoC★ 1
cve-2019-5420 POC simple ruby script
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir ↗Metasploit600
Wazuh server remote code execution caused by an unsafe deserialization vulnerability.
Remote code execution in Wazuh server
100RIESGO
abrir ↗GitHub PoC
skrkcb2/CVE-2024-5452
RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
53RIESGO
abrir ↗VulnCheck XDB
initial-access
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC★ 1
SSHEnum es una herramienta de enumeración de usuarios SSH basada en CVE-2018-15473. Permite detectar usuarios válidos aprovechando respuestas diferenciadas del servidor. Es rápida, compatible con Python 3.12 y soporta wordlists. Uso exclusivo para auditoría y pruebas de seguridad autorizadas.
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗GitHub PoC
RogelioPumajulca/CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC
0x7556/CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC
pz-frontend-manager < 1.0.6 - CSRF Profile Picture Exploit
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RIESGO
abrir ↗GitHub PoC
This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege escalation on Ubuntu 20.04 with sudo version 1.8.31 and glibc version 2.31. It includes an assembly-based exploit, a shared object payload, and a Makefile for automated compilation.
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC
PoC of CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 3
Snizi/Moodle-CVE-2024-43425-Exploit
Moodle: remote code execution via calculated question types
78RIESGO
abrir ↗VulnCheck XDB
infoleak
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit600
InvokeAI RCE
Remote Code Execution via Model Deserialization in invoke-ai/invokeai
63RIESGO
abrir ↗GitHub PoC★ 4
Cityworks deserialization of untrusted data vulnerability Detection
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to
83RIESGO
abrir ↗GitHub PoC★ 1
This is a Python script that exploits the CVE-2024-6624 vulnerability in the JSON API User <= 3.9.3 plugin for WordPress.
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RIESGO
abrir ↗GitHub PoC★ 4
Python script for CVE-2024-0012 / CVE-2024-9474 exploit
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir ↗VulnCheck XDB
initial-access
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir ↗GitHub PoC
Directory Traversal Exploit written in Bash for NVMS-1000 (CVE-2019-20085).
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.