Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.402exploits catalogados
34.906CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.861GitHub PoC 13.907VulnCheck XDB 8484Nuclei 4239Metasploit 3468✓ solo verificadosrecientespopularesriesgo
76.402 exploits
GitHub PoC★ 2
XSS to RCE in RenderTune v1.1.4 exploit
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML
48RIESGO
abrir ↗GitHub PoC★ 16
SPIP BigUp Plugin Unauthenticated RCE
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir ↗GitHub PoC
LiteSpeed Unauthorized Account Takeover
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗GitHub PoC★ 16
CVE-2024-44000 is a vulnerability in the LiteSpeed Cache plugin, a popular WordPress plugin. This vulnerability affects session management in LiteSpeed Cache, allowing attackers to gain unauthorized access to sensitive data.
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗VulnCheck XDB
local
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗GitHub PoC
test POC for CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗VulnCheck XDB
initial-access
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗Metasploit600
SPIP BigUp Plugin Unauthenticated RCE
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir ↗GitHub PoC
nteract 0.28.0 open redirect to RCE exploit
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
48RIESGO
abrir ↗GitHub PoC
deskfiler 1.2.3 Open Redirect exploit
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
48RIESGO
abrir ↗VulnCheck XDB
initial-access
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RIESGO
abrir ↗GitHub PoC
bryanqb07/CVE-2023-32315
Openfire administration console authentication bypass
100RIESGO
abrir ↗GitHub PoC★ 6
fru1ts/CVE-2024-44902
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RIESGO
abrir ↗GitHub PoC★ 12
Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 5
Research and PoC for CVE-2024-6386
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
53RIESGO
abrir ↗Metasploit600
Wordpress LiteSpeed Cache plugin cookie theft
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗GitHub PoC★ 1
This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC★ 4
Masamuneee/CVE-2024-4367-Analysis
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir ↗GitHub PoC★ 1
brownpanda29/Cve-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 1
Raffli-Dev/CVE-2023-41425
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗GitHub PoC★ 1
Adobe ColdFusion CVE-2023-26360/CVE-2023-29298 自动化实现反弹
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir ↗GitHub PoC★ 1
(CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC★ 3
Authenticated Code execution
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File
48RIESGO
abrir ↗GitHub PoC★ 8
This module exploits a vulnerability in the target service identified as CVE-2023-42115.
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.