Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.541Exploit-DB 24.485GitHub PoC 15.811VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
81.689 exploits
GitHub PoC
fredagsguf/Windows-CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗VulnCheck XDB
infoleak
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RIESGO
abrir ↗VulnCheck XDB
initial-access
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RIESGO
abrir ↗GitHub PoC★ 19
watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir ↗GitHub PoC
PoC for Watchguard CVE-2022-26318 updated to Python3.12
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RIESGO
abrir ↗GitHub PoC
Veeam Service Provider Console (VSPC) remote code execution.
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos
53RIESGO
abrir ↗GitHub PoC★ 1
Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en Chamilo LMS en versiones <= 1.11.24 permite a atacantes no autenticados realizar ataques de Cross Site Scripting almacenados y obtener código remoto ejecución mediante la carga de web shell.
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗VulnCheck XDB
infoleak
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗VulnCheck XDB
initial-access
Expedition: Missing Authentication Leads to Admin Account Takeover
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC
CVE-2024-10914 is a critical vulnerability affecting the D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L up to version 20241028. The function cgi_user_add in the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add is the culprit, allowing attackers to inject operating system commands remotely.
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗GitHub PoC
A utility for Magento 2 encryption key rotation and management. CVE-2024-34102(aka Cosmic Sting) victims can use it as an aftercare.
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗GitHub PoC★ 12
This repository contains a Proof of Concept (PoC) exploit for CVE-2024-11680, a critical vulnerability in ProjectSend r1605 and older versions. The exploit targets an improper authentication flaw due Privilege Misconfiguration issues.
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir ↗GitHub PoC★ 4
D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 4
based on [EQSTLab](https://github.com/EQSTLab)
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v
70RIESGO
abrir ↗GitHub PoC
A Proof-of-Concept (PoC) exploit for CVE-2018-16763 (Fuel CMS - Preauthenticated Remote Code Execution).
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗VulnCheck XDB
local
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RIESGO
abrir ↗GitHub PoC
Modified version of laravel ignition RCE (CVE-2021-3129) exploit script for Hour of Hack Session-4
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗GitHub PoC★ 1
This is a exploit for CVE-2024-50498
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir ↗Metasploit300
LINQPad Deserialization
LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(
36RIESGO
abrir ↗GitHub PoC
Hunt3r850/CVE-2024-10924-Wordpress-Docker
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC
Sebastianbedoya25/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.