Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.541Exploit-DB 24.485GitHub PoC 15.811VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
81.689 exploits
GitHub PoC★ 96
synacktiv/CVE-2024-43468
Microsoft Configuration Manager Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
76RIESGO
abrir ↗GitHub PoC★ 3
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗GitHub PoC★ 1
Proof Of Concept for the CVE-2012-1831 (Kingview Touchview 6.53). This is a Industrial Control Systems Vulnerability
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted p
28RIESGO
abrir ↗VulnCheck XDB
infoleak
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft Configuration Manager Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗VulnCheck XDB
infoleak
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir ↗GitHub PoC★ 3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir ↗GitHub PoC★ 1
Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗VulnCheck XDB
local
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RIESGO
abrir ↗VulnCheck XDB
infoleak
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir ↗VulnCheck XDB
initial-access
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir ↗GitHub PoC★ 3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗GitHub PoC
Picsmize <= 1.0.0 - Unauthenticated Arbitrary File Upload
WordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC
Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you cannot upgrade Magento or cannot apply the official patches, try this one.
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir ↗GitHub PoC
Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection
WordPress Lis Video Gallery plugin <= 0.2.1 - PHP Object Injection vulnerability
48RIESGO
abrir ↗GitHub PoC
Working Dirty Pipe (CVE-2022-0847) exploit tool with root access and file overwrites.
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir ↗GitHub PoC
WolffCorentin/CVE-2019-1663-Binary-Analysis
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir ↗GitHub PoC★ 1
Xss injection, WonderCMS 3.2.0 -3.4.2
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗GitHub PoC★ 1
Remote Command Execution into shell from a vulnerable exim service.
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗GitHub PoC
francescobrina/hfs-cve-2014-6287-exploit
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.