Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.175GitHub PoC 14.096VulnCheck XDB 8607Nuclei 4255Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.058 exploits
GitHub PoC
YangHyperData/LOGJ4_PocShell_CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 14
Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094
Xz: malicious code in distributed source
70RIESGO
abrir ↗Exploit-DB
Gibbon LMS v26.0.00 - SSTI vulnerability
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
53RIESGO
abrir ↗Exploit-DB
Daily Habit Tracker 1.0 - SQL Injection
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit
48RIESGO
abrir ↗Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
20RIESGO
abrir ↗Exploit-DB
Employee Management System 1.0 - _txtfullname_ and _txtphone_ SQL Injection
20RIESGO
abrir ↗Exploit-DB
GL-iNet MT6000 4.5.5 - Arbitrary File Download
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially
46RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 3
apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC★ 3
CVE-2024-3094 - Checker (fix for arch etc)
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC
Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC★ 1
This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo Application written with Node.js which is containing Remote Code Execution Vulnerability (CVE-2023-32314) for demonstrating all addvantages of this architecture to manage Honeypot systems
Sandbox Escape
48RIESGO
abrir ↗VulnCheck XDB
initial-access
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RIESGO
abrir ↗Exploit-DB
Axigen < 10.5.7 - Persistent Cross-Site Scripting
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges
48RIESGO
abrir ↗GitHub PoC★ 1
cjybao/CVE-2024-1709-and-CVE-2024-1708
Authentication bypass using an alternate path or channel
100RIESGO
abrir ↗VulnCheck XDB
local
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused
46RIESGO
abrir ↗GitHub PoC
This is my malware
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗GitHub PoC★ 1
galacticquest/cve-2024-3094-detect
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC★ 3
Herramientas de linux para diferentes funciones.
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC★ 17
XZ Backdoor Extract(Test on Ubuntu 23.10)
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC★ 4
Education purpose for CVE-2018-10933
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2024-20767 affecting Adobe ColdFusion
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.