Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.745Exploit-DB 24.485GitHub PoC 15.945VulnCheck XDB 9270Nuclei 4456Metasploit 3518✓ solo verificadosrecientespopularesriesgo
82.419 exploits
GitHub PoC
sigridou/CVE-2023-44487-
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir ↗Metasploit600
WordPress Backup Migration Plugin PHP Filter Chain RCE
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir ↗Metasploit600
GL.iNet Unauthenticated Remote Command Execution via the logread module.
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗Metasploit600
GL.iNet Unauthenticated Remote Command Execution via the logread module.
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000
36RIESGO
abrir ↗GitHub PoC
Porting the CVE-2020-0674 exploit for Windows8.1 and Windows10
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir ↗GitHub PoC
qailanet/cve-2022-41352-zimbra-rce
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RIESGO
abrir ↗GitHub PoC
PoC of CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
98RIESGO
abrir ↗VulnCheck XDB
client-side
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir ↗VulnCheck XDB
local
Windows Error Reporting Service Elevation of Privilege Vulnerability
98RIESGO
abrir ↗GitHub PoC★ 2
Exploit for CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗GitHub PoC★ 14
CVE-2023-20273 Exploit PoC
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RIESGO
abrir ↗GitHub PoC★ 1
Vulnerability in HTTP Protocol Stack Enabling Remote Code Execution and Potential System Crash.
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir ↗VulnCheck XDB
initial-access
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 27
An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all non-administator passwords, private keys and High Availability passwords.
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RIESGO
abrir ↗GitHub PoC
Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.
Unauthenticated sensitive information disclosure
100RIESGO
abrir ↗VulnCheck XDB
local
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RIESGO
abrir ↗GitHub PoC
Check for and remediate conditions that make an IOS-XE device vulnerable to CVE-2023-20198
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗GitHub PoC★ 8
CVE-2023-50643
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode a
48RIESGO
abrir ↗GitHub PoC★ 2
Instructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗GitHub PoC★ 1
POC&EXP for GlassFish<4.1.1(not including 4.1.1).
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir ↗GitHub PoC★ 2
Instructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
ag-rodriguez/CVE-2023-24078
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RIESGO
abrir ↗GitHub PoC★ 1
CVE-2023-28432 Minio Information isclosure Exploit
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.