Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.446Referência 22.166GitHub PoC 14.080VulnCheck XDB 8604Nuclei 4251Metasploit 3473✓ solo verificadosrecientespopularesriesgo
77.020 exploits
Metasploit600
DIAEnergie SQL Injection (CVE-2024-4548)
Delta Electronics DIAEnergie SQL Injection
48RIESGO
abrir ↗GitHub PoC★ 7
LINKSYS AC1900 EA7500v3 IGD UPnP Stack Buffer Overflow Remote Code Execution Vulnerability
Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP
48RIESGO
abrir ↗GitHub PoC★ 1
An issue in HSC Cybersecurity HSC Mailinspector version 5.2.17-3 has been identified, allowing a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive info
48RIESGO
abrir ↗GitHub PoC
GalloLuigi/Analisi-CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗VulnCheck XDB
initial-access
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir ↗GitHub PoC★ 2
PoC for the Untrusted Pointer Dereference in the appid.sys driver
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir ↗GitHub PoC
Turvanõrkuse CVE 2024 3273 analüüs: D-Link seadmete käsusüst
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC★ 1
FoxyProxys/CVE-2024-27956
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir ↗Metasploit600
Ollama Model Registry Path Traversal RCE
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,
78RIESGO
abrir ↗GitHub PoC
Vignesh2712/Automation-for-Juniper-cve-2023-36845
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
Joomla! v4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
Jenkins CVE-2024-23897: Arbitrary File Read Vulnerability
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC
CVE-2024-27956 WORDPRESS RCE PLUGIN
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir ↗GitHub PoC★ 7
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2024-21413 Microsoft Outlook RCE Exploit
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.10 - Local File Inclusion vulnerability
41RIESGO
abrir ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC
Bypass for CVE-2007-4559 Trellix patch
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RIESGO
abrir ↗GitHub PoC★ 7
Exploit for Microsoft SmartScreen malicious execution (april 2024)
SmartScreen Prompt Security Feature Bypass Vulnerability
83RIESGO
abrir ↗GitHub PoC
xsxtw/CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗GitHub PoC
xsxtw/CVE-2019-0232
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir ↗GitHub PoC
ShellUnease/CVE-2024-34833-payroll-management-system-rce
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settin
48RIESGO
abrir ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.