Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.322exploits catalogados
38.524CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.711Exploit-DB 24.485GitHub PoC 15.927VulnCheck XDB 9231Nuclei 4455Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.322 exploits
GitHub PoC★ 5
Simple scanner for scanning a list of ip-addresses for vulnerable Ivanti Pulse Secure devices
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗GitHub PoC
Exploit information for CVE-2023-26609
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗GitHub PoC
Proof of Concept script to exploit CVE-2023-42793 (TeamCity)
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi
60RIESGO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗GitHub PoC★ 5
CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗GitHub PoC
1.验证CVE-2016-4437、2.解析rememberMe的文件和CBC加密的IV偏移
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗VulnCheck XDB
infoleak
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗VulnCheck XDB
infoleak
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗GitHub PoC★ 10
Scanner for CVE-2023-46805 - Ivanti Connect Secure
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗GitHub PoC★ 7
POC Checker for ivanti CVE-2024-21887 Command injcetion
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir ↗VulnCheck XDB
initial-access
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir ↗GitHub PoC
Program ini adalah alat (tool) yang dibuat untuk memeriksa keamanan sistem Minio terkait dengan kerentanan CVE-2022-35919
Authenticated requests for server update admin API allows path traversal in minio
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗GitHub PoC★ 245
This repository presents a proof-of-concept of CVE-2023-7028
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗GitHub PoC
CVE-2023-7028 poc
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗GitHub PoC★ 58
CVE-2023-7028
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗GitHub PoC★ 3
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of S
35RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir ↗Metasploit300
GitLab Password Reset Account Takeover
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗Metasploit600
Netis router MW5360 unauthenticated RCE.
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter
65RIESGO
abrir ↗VulnCheck XDB
infoleak
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
75RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.