Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.175GitHub PoC 14.096VulnCheck XDB 8607Nuclei 4255Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.058 exploits
VulnCheck XDB
initial-access
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir ↗GitHub PoC★ 12
The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir ↗GitHub PoC★ 7
jakabakos/CVE-2023-43208-mirth-connect-rce-poc
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir ↗GitHub PoC★ 4
sxyrxyy/aiohttp-exploit-CVE-2024-23334-certstream
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir ↗Metasploit600
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
43RIESGO
abrir ↗Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
SpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadata
48RIESGO
abrir ↗VulnCheck XDB
initial-access
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir ↗Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
Authentication Bypass in OpenMetadata
85RIESGO
abrir ↗GitHub PoC★ 3
Exploit for Open eClass – CVE-2024-26503: Unrestricted File Upload Leads to Remote Code Execution
Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to
48RIESGO
abrir ↗GitHub PoC
exploit for f5-big-ip RCE cve-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 29
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir ↗VulnCheck XDB
local
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir ↗GitHub PoC
This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Exploit-DB
SolarView Compact 6.00 - Command Injection
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir ↗Exploit-DB
GitLab CE/EE < 16.7.2 - Password Reset
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗Metasploit600
Ghostscript Command Execution via Format String
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with
33RIESGO
abrir ↗Exploit-DB
KiTTY 0.76.1.13 - Command Injection
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RIESGO
abrir ↗Exploit-DB
Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)
Printer web page invalid command execution
75RIESGO
abrir ↗GitHub PoC
manrop2702/CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir ↗GitHub PoC
A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
53RIESGO
abrir ↗Exploit-DB
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RIESGO
abrir ↗Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf
41RIESGO
abrir ↗Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
Viessmann Vitogate 300 direct request
38RIESGO
abrir ↗Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir ↗GitHub PoC★ 150
out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir ↗GitHub PoC★ 16
Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.