Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.302 exploits
VulnCheck XDB
initial-access
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
Microsoft Office Remote Code Execution Vulnerability
41RIESGO
abrir ↗GitHub PoC★ 1
Expoit for CVE-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir ↗GitHub PoC★ 6
Perform With Massive Openfire Unauthenticated Users
Openfire administration console authentication bypass
100RIESGO
abrir ↗Metasploit600
OpenNMS Horizon Authenticated RCE
ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN
28RIESGO
abrir ↗Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
Remote Code Execution in OpenTSDB
68RIESGO
abrir ↗Metasploit600
OpenNMS Horizon Authenticated RCE
ROLE_REST can be used to escalate to ROLE_ADMIN via /rest/users
36RIESGO
abrir ↗Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
Remote Code Execution in OpenTSDB
75RIESGO
abrir ↗GitHub PoC★ 5
Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗VulnCheck XDB
initial-access
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗GitHub PoC
spip
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗GitHub PoC★ 9
WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir ↗GitHub PoC★ 11
Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
43RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir ↗VulnCheck XDB
infoleak
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 82
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir ↗GitHub PoC
yangshifan-git/CVE-2021-1732
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 4
Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
Hamesawian/CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗VulnCheck XDB
local
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗VulnCheck XDB
initial-access
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe
50RIESGO
abrir ↗VulnCheck XDB
local
Distros-[dirtyvma] privilege escalation via non-rcu-protected vma traversal
41RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.