Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.313 exploits
GitHub PoC
pedrochalegre7/CVE-2024-4367-pdf-sample
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir ↗GitHub PoC★ 6
WP REST API FNS <= 1.0.0 - Privilege Escalation
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RIESGO
abrir ↗GitHub PoC
1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover
WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
48RIESGO
abrir ↗GitHub PoC
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RIESGO
abrir ↗GitHub PoC★ 3
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗GitHub PoC★ 2
Meetup <= 0.1 - Authentication Bypass via Account Takeover
WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability
48RIESGO
abrir ↗GitHub PoC
Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Upload
WordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗GitHub PoC
guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗GitHub PoC★ 4
This repository contains a Crystallographic Information File (CIF) intended for use on the "Chemistry" machine on Hack The Box (HTB).
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir ↗GitHub PoC★ 3
WP Query Console <= 1.0 - Unauthenticated Remote Code Execution
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir ↗GitHub PoC
Signup Page <= 1.0 - Unauthenticated Arbitrary Options Update
WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability
48RIESGO
abrir ↗GitHub PoC
GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update
WordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability
48RIESGO
abrir ↗VulnCheck XDB
client-side
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RIESGO
abrir ↗GitHub PoC
Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RIESGO
abrir ↗GitHub PoC
POC firewall with rules designed to detect and block Spring4Shell vulnerability (CVE-2022-22965) exploit
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC★ 1
JAckLosingHeart/CVE-2024-51132-POC
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o
48RIESGO
abrir ↗GitHub PoC
CVE-2023-4220 Chamilo Exploit
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC★ 2
wp/ultimate-member - SQL Injection Vulnerability Exploit Script.
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗VulnCheck XDB
infoleak
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗VulnCheck XDB
client-side
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RIESGO
abrir ↗GitHub PoC
GodOfServer/CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗VulnCheck XDB
infoleak
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir ↗GitHub PoC
hualy13/CVE-2019-0708-Check
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.