Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.492GitHub PoC 14.286VulnCheck XDB 8703Nuclei 4314Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.724 exploits
VulnCheck XDB
initial-access
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir ↗GitHub PoC★ 10
CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2022-1609 WordPress Weblizar后门
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir ↗VulnCheck XDB
initial-access
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, an
35RIESGO
abrir ↗GitHub PoC
CVE-2018-17456复现
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir ↗VulnCheck XDB
initial-access
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir ↗GitHub PoC★ 2
FreePascal implementation of the vsFTPD 2.3.4 CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC
A PoC / methodology to exploit CVE-2017-6516
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RIESGO
abrir ↗GitHub PoC★ 1
sudo提权漏洞CVE-2021-3156复现代码
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC★ 5
Python script to exploit CVE-2022-29464 (mass mode)
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC
yuuki1967/CVE-2021-44228-Apache-Log4j-Rce
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (v2)
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
85RIESGO
abrir ↗GitHub PoC★ 71
Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
85RIESGO
abrir ↗GitHub PoC
b1ackros337/CVE-2020-25213
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit300
SuiteCRM authenticated SQL injection in export functionality
SQL Injection in salesagility/suitecrm
28RIESGO
abrir ↗GitHub PoC
Satheesh575555/external_expat_AOSP10_r33_CVE-2022-25235
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT
48RIESGO
abrir ↗GitHub PoC★ 1
SDT-CW3B1 1.1.0 - OS Command Injection
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RIESGO
abrir ↗VulnCheck XDB
initial-access
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
50RIESGO
abrir ↗GitHub PoC★ 3
Initial POC for the CVE-2022-30525
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir ↗GitHub PoC★ 1
Tinker Script for CVE-2022-23046
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.