Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.302 exploits
VulnCheck XDB
initial-access
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RIESGO
abrir ↗GitHub PoC
ohnonoyesyes/CVE-2023-32315
Openfire administration console authentication bypass
100RIESGO
abrir ↗GitHub PoC★ 1
y0d3n/CVE-2014-0094
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir ↗GitHub PoC★ 6
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RIESGO
abrir ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
Code Injection in pyload/pyload
85RIESGO
abrir ↗VulnCheck XDB
initial-access
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sales Tracker Management System v1.0 - Multiple Vulnerabilities
SourceCodester Sales Tracker Management System cross site scripting
28RIESGO
abrir ↗VulnCheck XDB
initial-access
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val
60RIESGO
abrir ↗Exploit-DB
Teachers Record Management System 1.0 - File Upload Type Validation
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
33RIESGO
abrir ↗VulnCheck XDB
infoleak
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗GitHub PoC
Proof of Concept for vulnerability CVE-2023-2986 in 'Abandoned Cart Lite for WooCommerce' Plugin in WordPress in Python Version
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RIESGO
abrir ↗GitHub PoC★ 229
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RIESGO
abrir ↗GitHub PoC★ 2
python program to exploit CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir ↗VulnCheck XDB
initial-access
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RIESGO
abrir ↗GitHub PoC
Python 2.7
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗GitHub PoC
Sonatype Nexus 3.21.01 - Remote Code Execution (Authenticated - Updated)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir ↗GitHub PoC★ 64
CVE-2023-34362: MOVEit Transfer Unauthenticated RCE
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗GitHub PoC★ 3
A script, written in golang. POC for CVE-2023-25157
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir ↗Metasploit600
Apache NiFi H2 Connection String Remote Code Execution
Apache NiFi: Potential Code Injection with Database Services using H2
48RIESGO
abrir ↗VulnCheck XDB
initial-access
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗VulnCheck XDB
local
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RIESGO
abrir ↗VulnCheck XDB
initial-access
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.