Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.107 exploits
VulnCheck XDB
initial-access
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir ↗VulnCheck XDB
infoleak
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir ↗GitHub PoC
Import Export For WooCommerce <= 1.5 - Authenticated (Subscriber+) Arbitrary File Upload
WordPress Import Export For WooCommerce plugin <= 1.6.2 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗Metasploit600
Craft CMS Twig Template Injection RCE via FTP Templates Path
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗GitHub PoC
Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation
WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
48RIESGO
abrir ↗GitHub PoC★ 3
test code for cve-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC★ 1
yiliufeng168/CVE-2024-50379-POC
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir ↗GitHub PoC★ 1
webmin or minisever RCE
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗Metasploit600
Windows Cloud File Mini Filer Driver Heap Overflow
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗VulnCheck XDB
initial-access
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗GitHub PoC★ 1
Adobe ColdFusion 8 - Remote Command Execution (RCE)
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir ↗GitHub PoC★ 2
dustblessnotdust/CVE-2024-53677-S2-067-thread
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗GitHub PoC★ 4
v3153/CVE-2024-50379-POC
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir ↗GitHub PoC★ 3
A Docker-based environment to reproduce the CVE-2024-53677 vulnerability in Apache Struts 2.
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗GitHub PoC★ 3
yangyanglo/CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗GitHub PoC★ 6
Proof of concept (POC) for CVE-2024-45337
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RIESGO
abrir ↗GitHub PoC★ 1
An example project that showcases golang code vulnerable to CVE-2024-45337
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
95RIESGO
abrir ↗Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 1
The EXP/POC of CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗GitHub PoC
redspy-sec/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.