Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.651Exploit-DB 24.485GitHub PoC 15.884VulnCheck XDB 9215Nuclei 4454Metasploit 3513✓ solo verificadosrecientespopularesriesgo
81.859 exploits
GitHub PoC★ 31
POC for CVE-2024-34102. A pre-authentication XML entity injection issue in Magento / Adobe Commerce.
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗GitHub PoC★ 8
🆘New Windows Kernel Priviledge Escalation Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir ↗Exploit-DB
SolarWinds Platform 2024.1 SR1 - Race Condition
SolarWinds Platform Race Condition Vulnerability
38RIESGO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 1
The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗Metasploit300
Fortra FileCatalyst Workflow SQL Injection (CVE-2024-5276)
SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
65RIESGO
abrir ↗Metasploit300
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
MOVEit Transfer Authentication Bypass Vulnerability
85RIESGO
abrir ↗GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
CVE-2024-6028 Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RIESGO
abrir ↗GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗GitHub PoC
zerobytesecure/CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗GitHub PoC★ 1
Proof of concept of CVE-2024-29868 affecting Apache StreamPipes from 0.69.0 through 0.93.0
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RIESGO
abrir ↗GitHub PoC
CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗GitHub PoC★ 45
Exploit for the CVE-2024-5806
MOVEit Transfer Authentication Bypass Vulnerability
85RIESGO
abrir ↗GitHub PoC★ 1
This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)
Argument Injection in PHP-CGI
100RIESGO
abrir ↗GitHub PoC★ 290
tykawaii98/CVE-2024-30088
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir ↗VulnCheck XDB
infoleak
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗GitHub PoC
PoC and analysis for Kibana Prototype Pollution RCE (CVE-2019-7609).
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗GitHub PoC★ 40
tykawaii98/CVE-2024-21338_PoC
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.