Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.313 exploits
VulnCheck XDB
initial-access
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗GitHub PoC
To test elasticsearch vulnerabillity on newer version of debian
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir ↗GitHub PoC
In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
oxapavan/CVE-2023-4220-HTB-PermX
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC★ 14
Exploit for cve-2024-10914: D-Link DNS-320, DNS-320LW, DNS-325, DNS-340L Version 1.00, Version 1.01.0914.2012, Version 1.01, Version 1.02, Version 1.08 Command Injection
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗VulnCheck XDB
infoleak
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗GitHub PoC★ 3
WP Sessions Time Monitoring Full Automatic <= 1.0.9 - Unauthenticated SQL Injection
WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.0.9 - SQL Injection vulnerability
48RIESGO
abrir ↗VulnCheck XDB
initial-access
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RIESGO
abrir ↗GitHub PoC
Ajar in5 Embed <= 3.1.3 - Unauthenticated Arbitrary File Upload
WordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗GitHub PoC
WP Dropbox Dropins <= 1.0 - Unauthenticated Arbitrary File Upload
WordPress WP Dropbox Dropins plugin <= 1.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗GitHub PoC★ 1
Proof of concept of the parh traversal in python AioHTTP library =< 3.9.1
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir ↗GitHub PoC
CVE-2024-4898 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
63RIESGO
abrir ↗GitHub PoC
WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion
WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion
60RIESGO
abrir ↗GitHub PoC
Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RIESGO
abrir ↗GitHub PoC
SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Authenticated (Subscriber+) Arbitrary File Upload
WordPress SurveyJS plugin <= 1.9.136 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗VulnCheck XDB
initial-access
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir ↗VulnCheck XDB
local
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir ↗GitHub PoC
CVE-2023-25813 Vulnerability Reproduction - SQL Injection in Sequelize
SQL Injection via replacements in sequelize
48RIESGO
abrir ↗GitHub PoC
Exploit Development for CVE-2023-6553 on Backup Plugin in Wordpress
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir ↗GitHub PoC★ 1
0xR00/CVE-2024-23334
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir ↗GitHub PoC★ 1
cbyerpanel rce exploit
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir ↗GitHub PoC★ 98
Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir ↗GitHub PoC★ 1
AliHj98/cve-2024-38063-Anonyvader
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗VulnCheck XDB
initial-access
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir ↗VulnCheck XDB
initial-access
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir ↗VulnCheck XDB
initial-access
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.