Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
77.813 exploits
GitHub PoC
CVE-2014-1767在win7_x64平台的EXP和分析文章
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthenticated)
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RIESGO
abrir ↗GitHub PoC
docker lab setup for kibana-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗GitHub PoC
puckiestyle/CVE-2022-20699
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗Exploit-DB
Hospital Management Startup 1.0 - 'Multiple' SQLi
HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
23RIESGO
abrir ↗GitHub PoC★ 2
An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows a Local Or Remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
28RIESGO
abrir ↗Exploit-DB
AtomCMS v2.0 - SQLi
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
50RIESGO
abrir ↗Metasploit300
Strapi CMS Unauthenticated Password Reset
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir ↗Exploit-DB
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
Security Audit <= 1.0.0 - Admin+ Stored Cross Site Scripting
23RIESGO
abrir ↗GitHub PoC★ 795
Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)
Windows Print Spooler Elevation of Privilege Vulnerability
98RIESGO
abrir ↗Exploit-DB
Hospital Management System 4.0 - 'multiple' SQL Injection
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
23RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RIESGO
abrir ↗Exploit-DB
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir ↗Exploit-DB
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use
23RIESGO
abrir ↗Metasploit300
CVE-2022-21999 SpoolFool Privesc
Windows Print Spooler Elevation of Privilege Vulnerability
98RIESGO
abrir ↗GitHub PoC
CVE-2012-1876 win7_x86和x64平台分析,EXP、POC代码和分析文档
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
CP Blocks < 1.0.15 - Admin+ Stored Cross-Site Scripting
23RIESGO
abrir ↗VulnCheck XDB
local
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir ↗GitHub PoC★ 2
Worm written in python, abuses CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir ↗GitHub PoC★ 10
kernel exploit
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir ↗Metasploit200
Netfilter nft_set_elem_init Heap Overflow Privilege Escalation
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buff
38RIESGO
abrir ↗GitHub PoC★ 237
Cisco Anyconnect VPN unauth RCE (rwx stack)
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir ↗GitHub PoC★ 6
Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.