Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
81.759 exploits
GitHub PoC★ 1
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
63RIESGO
abrir ↗GitHub PoC
Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS
Remote Code Execution (RCE)
48RIESGO
abrir ↗VulnCheck XDB
local
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RIESGO
abrir ↗GitHub PoC★ 2
Nortek Linear eMerge E3 Pre-Auth RCE PoC (CVE-2024-9441)
Linear eMerge e3-Series Forgot Password Command Injection
60RIESGO
abrir ↗VulnCheck XDB
client-side
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir ↗GitHub PoC★ 3
CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗GitHub PoC★ 1
Wechat Social login <= 1.3.0 - Authentication Bypass
Wechat Social login <= 1.3.0 - Authentication Bypass
48RIESGO
abrir ↗GitHub PoC★ 5
This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The script uses Scapy to send various types of requests (ICMP, ARP, or TCP) and checks if the responses contain any padding data that could potentially leak sensitive memory contents.
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RIESGO
abrir ↗Exploit-DB
openSIS 9.1 - SQLi (Authenticated)
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
41RIESGO
abrir ↗VulnCheck XDB
initial-access
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RIESGO
abrir ↗GitHub PoC★ 8
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC★ 11
POC - Jenkins File Read Vulnerability - CVE-2024-23897
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC★ 12
GiveWP PHP Object Injection exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RIESGO
abrir ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗GitHub PoC★ 10
CVE-2021-3129 (Laravel Ignition RCE Exploit)
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗GitHub PoC★ 6
PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing server responses
Information disclosure
100RIESGO
abrir ↗GitHub PoC★ 8
p33d/CVE-2024-43917
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RIESGO
abrir ↗VulnCheck XDB
infoleak
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RIESGO
abrir ↗GitHub PoC★ 42
p33d/CVE-2024-45519
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir ↗VulnCheck XDB
infoleak
CVE-2024-38816: Path traversal vulnerability in functional web frameworks
61RIESGO
abrir ↗VulnCheck XDB
initial-access
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗GitHub PoC★ 1
GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗VulnCheck XDB
infoleak
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RIESGO
abrir ↗GitHub PoC★ 1
ADManager Plus Build < 7210 Elevation of Privilege Vulnerability
Privilege Escalation
41RIESGO
abrir ↗GitHub PoC★ 1
This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a **malicious RAR archive** that triggers the execution of arbitrary code when the victim opens a benign-looking file within the archive (such as a PDF).
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.