Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.451exploits catalogados
38.590CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.767Exploit-DB 24.485GitHub PoC 15.955VulnCheck XDB 9270Nuclei 4456Metasploit 3518✓ solo verificadosrecientespopularesriesgo
82.451 exploits
GitHub PoC
RCE PoC for Apache Commons Text vuln
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RIESGO
abrir ↗GitHub PoC★ 28
jakabakos/CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗Exploit-DB
Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information
23RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Elementor 3.5.5 - Iframe Injection
Elementor < 3.5.5 - Iframe Injection
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗Exploit-DB
Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12
50RIESGO
abrir ↗GitHub PoC★ 9
A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
50RIESGO
abrir ↗Exploit-DB
SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
SPA-Cart eCommerce CMS GET Parameter search sql injection
45RIESGO
abrir ↗GitHub PoC
Hikikan/CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir ↗VulnCheck XDB
infoleak
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
50RIESGO
abrir ↗VulnCheck XDB
initial-access
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 7
An exploit for OpenTSDB <= 2.4.1 cmd injection (CVE-2023-36812/CVE-2023-25826) written in Fortran
Remote Code Execution in OpenTSDB
68RIESGO
abrir ↗VulnCheck XDB
initial-access
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗GitHub PoC★ 2
SUPRAAA-1337/CVE-2021-20021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account
100RIESGO
abrir ↗VulnCheck XDB
client-side
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir ↗GitHub PoC
Quick exploit builder for CVE-2023-38831, a vulnerability that affects WinRAR versions before 6.23.
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗GitHub PoC
This is a PoC for CVE-2023-27372 and spawns a fully interactive shell.
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗GitHub PoC
Text4Shell
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗Metasploit400
Apache Superset Signed Cookie RCE
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗Metasploit400
Apache Superset Signed Cookie RCE
Apache Superset: Metadata db write access can lead to remote code execution
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir ↗Metasploit400
Apache Superset Signed Cookie RCE
Apache Superset: Possible Unauthorized Registration of SQLite Database Connections
45RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗VulnCheck XDB
initial-access
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RIESGO
abrir ↗GitHub PoC★ 1
Script to exploit CVE-2023-38035
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC★ 11
Automated vulnerability scanner for CVE-2023-28432 in Minio deployments, revealing sensitive environment variables.
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.