Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.483Referência 24.469GitHub PoC 15.768VulnCheck XDB 9182Nuclei 4447Metasploit 3510✓ solo verificadosrecientespopularesriesgo
81.524 exploits
GitHub PoC★ 2
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir ↗GitHub PoC★ 407
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗GitHub PoC
CVE-2024-9047, wfu_file_downloader.php
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RIESGO
abrir ↗GitHub PoC
DavidBr27/CVE-2013-3900-Remediation-Script
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗GitHub PoC
RCE, Citirx ADC and Gateway Directory Traversal
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗VulnCheck XDB
client-side
Improper multimedia file attachment validation in Telegram for Android app
41RIESGO
abrir ↗VulnCheck XDB
infoleak
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗GitHub PoC
ishwardeepp/CVE-2025-22604-Cacti-RCE
Cacti has Authenticated RCE via multi-line SNMP responses
48RIESGO
abrir ↗GitHub PoC★ 2
CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vulnerability
WordPress The Novel Design Store Directory plugin <= 4.3.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗GitHub PoC★ 2
One-Click-Root program based on CVE-2016-5195, that works on the old 'PlayStation Certified' android devices
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗GitHub PoC
Webmin 1.580 /file/show.cgi Remote Code Execution
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir ↗GitHub PoC
DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir ↗GitHub PoC
redpack-kr/CVE-2025-26319
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RIESGO
abrir ↗GitHub PoC★ 197
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC★ 11
cve-2025-24813验证脚本
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC
Pei4AN/CVE-2025-28915
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC★ 1
User name enumeration against SSH daemons affected by CVE-2016-6210.
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir ↗GitHub PoC★ 3
CVE-2025-24813_POC
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC★ 1
Security Researcher
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.