Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.302 exploits
GitHub PoC★ 1
isacaya/CVE-2019-11358
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir ↗VulnCheck XDB
client-side
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir ↗VulnCheck XDB
infoleak
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RIESGO
abrir ↗GitHub PoC★ 3
This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on Ubuntu 5.8.0-48-generic and COS 5.4.89+. Use responsibly and ethically.
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir ↗Exploit-DB
PHPJabbers Taxi Booking 2.0 - Reflected XSS
PHP Jabbers Taxi Booking index.php cross site scripting
48RIESGO
abrir ↗GitHub PoC★ 2
CVE-2023-37979 PoC and Checker
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RIESGO
abrir ↗Exploit-DB
PHPJabbers Rental Property Booking 2.0 - Reflected XSS
PHP Jabbers Rental Property Booking index.php cross site scripting
33RIESGO
abrir ↗GitHub PoC
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor Homepage: https://github.com/pluck-cms/pluck # Version: 4.7.16 # Tested on Ubuntu 20.04.3 LTS # CVE: CVE-2022-26965
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RIESGO
abrir ↗Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
EventON < 2.1.2 - Unauthenticated Event Access
50RIESGO
abrir ↗Exploit-DB
PHPJabbers Night Club Booking 1.0 - Reflected XSS
PHP Jabbers Night Club Booking Software index.php cross site scripting
48RIESGO
abrir ↗Exploit-DB
Shelly PRO 4PM v0.11.0 - Authentication Bypass
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RIESGO
abrir ↗GitHub PoC
Vulnerable environment of CVE-2020-17530 (S2-061) for testing
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir ↗Exploit-DB
PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
PHP Jabbers Shuttle Booking Software index.php cross site scripting
48RIESGO
abrir ↗Exploit-DB
PHPJabbers Cleaning Business 1.0 - Reflected XSS
PHP Jabbers Cleaning Business index.php cross site scripting
48RIESGO
abrir ↗Exploit-DB
PHPJabbers Service Booking Script 1.0 - Reflected XSS
PHP Jabbers Service Booking Script index.php cross site scripting
48RIESGO
abrir ↗Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RIESGO
abrir ↗Exploit-DB
WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RIESGO
abrir ↗GitHub PoC★ 4
Remote Unauthenticated API Access Vulnerability in MobileIron Core 11.2 and older
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RIESGO
abrir ↗VulnCheck XDB
initial-access
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RIESGO
abrir ↗GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir ↗Metasploit600
LG Simple Editor Command Injection (CVE-2023-40504)
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability
65RIESGO
abrir ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗GitHub PoC
726232111/CVE-2023-28252
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir ↗GitHub PoC
overgrowncarrot1/DejaVu-CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir ↗GitHub PoC★ 3
Python Interactive Exploit for WP File Manager Vulnerability. The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension.
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.