Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.937VulnCheck XDB 8510Nuclei 4239Metasploit 3468✓ solo verificadosrecientespopularesriesgo
76.496 exploits
VulnCheck XDB
initial-access
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗GitHub PoC★ 7
Fully automated PoC - CVE-2024-25641 - RCE - Cacti < v1.2.26 🌵
Cacti RCE vulnerability when importing packages
85RIESGO
abrir ↗GitHub PoC★ 1
In an era where digital security is crucial, a new vulnerability in OpenSSH, identified as CVE-2024-6387, has drawn the attention of system administrators and security professionals worldwide. Named "regreSSHion," this severe security flaw allows remote code execution (RCE) and could significant threat to the integrity of vulnerable systems.
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC★ 83
mistymntncop/CVE-2024-5274
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir ↗GitHub PoC
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RIESGO
abrir ↗GitHub PoC★ 6
This exploit will attempt to execute system commands on SPIP targets.
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir ↗GitHub PoC★ 7
potential memory corruption vulnerabilities in IPv6 networks.
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 2
Remotely Exploiting The Kernel Via IPv6
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 4
Windows TCP/IP IPv6(CVE-2024-38063)
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 2
This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC
Apache: a Mainstream Web Service Turned a Vector of Attack for Remote Code Execution
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 2
D0rDa4aN919/CVE-2023-22809-Exploiter
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗GitHub PoC★ 3
Apache OFBiz CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗GitHub PoC★ 1
【Teedy 1.11】Account Takeover via XSS
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
41RIESGO
abrir ↗VulnCheck XDB
local
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir ↗Metasploit600
Moodle Remote Code Execution (CVE-2024-43425)
Moodle: remote code execution via calculated question types
78RIESGO
abrir ↗GitHub PoC★ 2
PoC for CVE-2024-25641 Authenticated RCE on Cacti v1.2.26
Cacti RCE vulnerability when importing packages
85RIESGO
abrir ↗GitHub PoC★ 1
Nuclei template to scan for Apache Ofbiz affecting versions before 18.12.15
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗GitHub PoC
CVE-2023-4220 Chamilo Exploit
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC★ 10
CVE-2024-25641 - RCE Automated Exploit - Cacti 1.2.26
Cacti RCE vulnerability when importing packages
85RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗GitHub PoC★ 7
PoC for the CVE-2024 Litespeed Cache Privilege Escalation
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗GitHub PoC★ 4
Jelly Template Injection Vulnerability in ServiceNow | POC CVE-2024-4879
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir ↗GitHub PoC★ 4
Mass scanner for CVE-2024-36401
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.