Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.401 exploits
VulnCheck XDB
remote-with-credentials
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RIESGO
abrir ↗GitHub PoC
2022 Spring Prof. 謝續平
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir ↗VulnCheck XDB
initial-access
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir ↗GitHub PoC
ShyTangerine/cve-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗VulnCheck XDB
infoleak
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir ↗Metasploit600
Ivanti Avalanche FileStoreConfig File Upload
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could
58RIESGO
abrir ↗GitHub PoC★ 1
RubXkuB/PoC-Metabase-CVE-2021-41277
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir ↗GitHub PoC★ 13
CVE-2023-22894
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RIESGO
abrir ↗GitHub PoC★ 16
CVE-2023-1671-POC, based on dnslog platform
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir ↗GitHub PoC
andyhsu024/CVE-2021-29447
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir ↗VulnCheck XDB
initial-access
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir ↗GitHub PoC
msd0pe-1/CVE-2023-31747
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RIESGO
abrir ↗VulnCheck XDB
initial-access
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l
83RIESGO
abrir ↗GitHub PoC★ 1
glen-pearson/ProxyLogon-CVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 3
Pre-Auth RCE in Sophos Web Appliance
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir ↗VulnCheck XDB
initial-access
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir ↗GitHub PoC★ 55
Proof of Concept Exploit for PaperCut CVE-2023-27350
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗GitHub PoC★ 2
「💥」CVE-2022-4944: KodExplorer <= 4.49 - CSRF to Arbitrary File Upload
kalcaddle KodExplorer cross-site request forgery
33RIESGO
abrir ↗Metasploit300
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via t
36RIESGO
abrir ↗GitHub PoC★ 12
imancybersecurity/CVE-2023-27350-POC
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗GitHub PoC
Anonimo501/ssh_enum_users_CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗GitHub PoC★ 5
A simple python script to check if a service is vulnerable
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.