Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.937VulnCheck XDB 8510Nuclei 4239Metasploit 3468✓ solo verificadosrecientespopularesriesgo
76.496 exploits
VulnCheck XDB
client-side
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗GitHub PoC
Python3 toolkit update
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗GitHub PoC★ 9
0xRoqeeb/sqlpad-rce-exploit-CVE-2022-0944
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir ↗GitHub PoC★ 5
CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗GitHub PoC★ 1
Scanning CVE-2024-4577 vulnerability with a url list.
Argument Injection in PHP-CGI
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 3
Analysis , Demo exploit and poc about CVE-2024-37084
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RIESGO
abrir ↗GitHub PoC★ 1
Artemisxxx37/OverlayFS-PrivEsc-CVE-2022-0944
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗GitHub PoC★ 1
KaoXx/CVE-2022-37706
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗GitHub PoC★ 1
CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗GitHub PoC
PoC code written for CVE-2022-0944 to make exploitation easier. Based on information found here: https://huntr.com/bounties/46630727-d923-4444-a421-537ecd63e7fb
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir ↗GitHub PoC★ 5
SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944])
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir ↗GitHub PoC
CVE-2024-23897 분석
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC★ 4
CVE-2018-0834 full code exec
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RIESGO
abrir ↗GitHub PoC★ 7
A proof of concept exploit for SQLPad RCE (CVE-2022-0944).
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir ↗VulnCheck XDB
infoleak
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RIESGO
abrir ↗GitHub PoC★ 4
A proof of concept of the LFI vulnerability on aiohttp 3.9.1
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir ↗GitHub PoC
quick powershell script to fix cve-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 5
🔥 CVE-2024-44849 Exploit
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
75RIESGO
abrir ↗Metasploit600
SPIP BigUp Plugin Unauthenticated RCE
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir ↗GitHub PoC
deskfiler 1.2.3 Open Redirect exploit
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
48RIESGO
abrir ↗GitHub PoC★ 2
XSS to RCE in RenderTune v1.1.4 exploit
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML
48RIESGO
abrir ↗GitHub PoC
nteract 0.28.0 open redirect to RCE exploit
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.