Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.745exploits catalogados
38.712CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.884Exploit-DB 24.485GitHub PoC 16.068VulnCheck XDB 9333Nuclei 4457Metasploit 3518✓ solo verificadosrecientespopularesriesgo
82.745 exploits
GitHub PoC★ 65
mandiant/citrix-ioc-scanner-cve-2023-3519
Unauthenticated remote code execution
100RIESGO
abrir ↗GitHub PoC★ 52
PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗VulnCheck XDB
client-side
PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
38RIESGO
abrir ↗GitHub PoC
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗VulnCheck XDB
initial-access
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir ↗VulnCheck XDB
infoleak
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir ↗VulnCheck XDB
initial-access
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir ↗Metasploit600
PRTG CVE-2023-32781 Authenticated RCE
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an au
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Social-Commerce 3.1.6 - Reflected XSS
mooSocial mooStore cross site scripting
43RIESGO
abrir ↗Exploit-DB
Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RIESGO
abrir ↗Metasploit600
CrushFTP Unauthenticated RCE
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes
60RIESGO
abrir ↗Exploit-DB
Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
Templatecookie Adlisting Redirect ad-list information disclosure
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mooSocial 3.1.8 - Reflected XSS
mooSocial mooStore index cross site scripting
43RIESGO
abrir ↗Exploit-DB
Emagic Data Center Management Suite v6.0 - OS Command Injection
OS Command Injection Vulnerability in Emagic Data Center Management Suite
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
68RIESGO
abrir ↗VulnCheck XDB
client-side
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
43RIESGO
abrir ↗GitHub PoC
Original Exploit Source: https://www.exploit-db.com/exploits/46635
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗GitHub PoC
Campcodes Online Matrimonial Website System 3.3 Cross Site Scripting
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RIESGO
abrir ↗GitHub PoC★ 10
CVE exploitation for WebKit jsc CVE-2018-4416
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RIESGO
abrir ↗GitHub PoC★ 2
Running this exploit on a vulnerable system allows a local attacker to gain a root shell on the machine.
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗VulnCheck XDB
local
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗GitHub PoC
MrE-Fog/jboss-_CVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir ↗VulnCheck XDB
initial-access
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir ↗GitHub PoC★ 2
Perform With Massive Authentication Bypass (Wordpress Mstore-API)
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir ↗VulnCheck XDB
infoleak
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.