Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.401 exploits
Exploit-DB✓ VexDay Proof
Online Security Guards Hiring System 1.0 - Reflected XSS
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Faculty Evaluation System 1.0 - Unauthenticated File Upload
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u
61RIESGO
abrir ↗GitHub PoC★ 1
Exploit for CVE:2010-2075. This exploit allows remote command execution in UnrealIRCd 3.2.8.1.
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir ↗Exploit-DB
unilogies/bumsys v1.0.3 beta - Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type in unilogies/bumsys
41RIESGO
abrir ↗VulnCheck XDB
initial-access
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗GitHub PoC
the proof of concept written in Python for an unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. This is a critical severity issue
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir ↗GitHub PoC★ 62
I5N0rth/CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir ↗GitHub PoC★ 1
eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's password in plain text.
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2
48RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir ↗GitHub PoC★ 6
WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗GitHub PoC★ 8
The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗VulnCheck XDB
denial-of-service
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir ↗GitHub PoC
kw3h4/CVE-2023-21839-metasploit-scanner
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir ↗GitHub PoC★ 2
Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir ↗Metasploit600
Dolibarr ERP/CRM Authenticated Code Injection
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instea
58RIESGO
abrir ↗GitHub PoC★ 1
MinIO Information Disclosure Vulnerability scanner by metasploit
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir ↗GitHub PoC★ 2
Perfom With Massive Authentication Bypass In PaperCut MF/NG
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗GitHub PoC★ 2
Exploit for Bad Binder
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir ↗GitHub PoC★ 1
PoC for login with password hash in STARFACE
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RIESGO
abrir ↗VulnCheck XDB
initial-access
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir ↗GitHub PoC★ 2
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir ↗Metasploit600
Openfire authentication bypass with RCE plugin
Openfire administration console authentication bypass
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RIESGO
abrir ↗VulnCheck XDB
initial-access
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.