Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.594Exploit-DB 24.485GitHub PoC 15.871VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
81.759 exploits
VulnCheck XDB
initial-access
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RIESGO
abrir ↗VulnCheck XDB
infoleak
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RIESGO
abrir ↗VulnCheck XDB
infoleak
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir ↗GitHub PoC★ 19
Exploit for CVE-2024-29847
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows
60RIESGO
abrir ↗GitHub PoC★ 2
chsxthwik/CVE-2024-2876
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir ↗GitHub PoC★ 3
Proof-of-Concept Exploit for CVE-2024-36401 GeoServer 2.25.1
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute
43RIESGO
abrir ↗GitHub PoC
🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker successfully bypassed authentication, gaining admin control over the device! Immediate containment was critical. Stay vigilant! 💻🔐
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗GitHub PoC★ 2
Robocopsita/CVE-2022-0944_RCE_POC
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir ↗GitHub PoC
acidburn2049/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC
sshipanoo/CVE-2024-44542
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.
48RIESGO
abrir ↗GitHub PoC
0xWhoami35/CVE-2024-4879
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir ↗VulnCheck XDB
initial-access
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗GitHub PoC
🚨 New Incident Report Completed! 🚨 Just wrapped up "Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)" on LetsDefend.io. This analysis involved investigating an attempted Command Injection targeting our PHP server. Staying ahead of these threats with continuous monitoring and swift containment! 🛡️
Argument Injection in PHP-CGI
100RIESGO
abrir ↗GitHub PoC
Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)
Authentication bypass using an alternate path or channel
100RIESGO
abrir ↗GitHub PoC
pwning netconsd
netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could
48RIESGO
abrir ↗GitHub PoC
Old weaponized CVE-2022-1388 exploit.
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗GitHub PoC
Event ID 189 Rule Name SOC227 Microsoft SharePoint Server Elevation of Privilege Possible CVE-2023-29357 .. Exploitation
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC
CVE-2024-8277 - 0Day Auto Exploit Authentication Bypass in WooCommerce Photo Reviews Plugin
WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation
48RIESGO
abrir ↗GitHub PoC
OtisSymbos/CVE-2021-44228-Log4Shell-
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
Log4J exploit CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Metasploit300
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RIESGO
abrir ↗Metasploit300
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.