Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.937VulnCheck XDB 8510Nuclei 4239Metasploit 3468✓ solo verificadosrecientespopularesriesgo
76.496 exploits
GitHub PoC★ 4
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 695
poc for CVE-2024-38063 (RCE in tcpip.sys)
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 1
Python exploit for Chamilo Unrestricted File Upload Vuln - CVE-2023-4220
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC★ 3
Telerik Report Server deserialization and authentication bypass exploit chain for CVE-2024-4358/CVE-2024-1800
Registration Authentication Bypass Vulnerability
100RIESGO
abrir ↗GitHub PoC
TeamCity CVE-2023-42793 RCE (Remote Code Execution)
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗GitHub PoC★ 24
LiteSpeed Cache Privilege Escalation PoC
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗GitHub PoC★ 2
CVE-2024-38063 research so you don't have to.
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 19
Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)
Moodle: remote code execution via calculated question types
78RIESGO
abrir ↗Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RIESGO
abrir ↗GitHub PoC★ 2
Windows远程桌面授权服务CVE-2024-38077检测工具
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
Traccar's unrestricted file upload vulnerability in device image upload could lead to remote code execution
48RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir ↗GitHub PoC
Research
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗Metasploit300
SolarWinds Web Help Desk Backdoor (CVE-2024-28987)
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 9
CVE-2024-38856 Exploit
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗VulnCheck XDB
local
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RIESGO
abrir ↗VulnCheck XDB
infoleak
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir ↗GitHub PoC
MLflow LFI/RFI Vulnerability -CVE-2023-1177 - Reproduced
Path Traversal: '\..\filename' in mlflow/mlflow
75RIESGO
abrir ↗GitHub PoC★ 1
CVE-2023-7028 POC && Exploit
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗GitHub PoC★ 3
Proof-of-Concept for CVE-2024-5932 GiveWP PHP Object Injection
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RIESGO
abrir ↗GitHub PoC★ 25
PHP CGI Argument Injection (CVE-2024-4577) RCE
Argument Injection in PHP-CGI
100RIESGO
abrir ↗GitHub PoC
A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the registry to reduce the risk of exploitation without needing the immediate installation of the official Microsoft KB update. Intended as a temporary fix
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC
Unauthenticated Remote Code Execution – Bricks
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗GitHub PoC
A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary workaround. This repository helps secure systems against potential remote code execution risks associated with affected OpenSSH versions.
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.