Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
77.813 exploits
VulnCheck XDB
client-side
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗Exploit-DB
VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RIESGO
abrir ↗VulnCheck XDB
initial-access
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
83RIESGO
abrir ↗GitHub PoC★ 5
lsw29475/CVE-2020-9715
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
83RIESGO
abrir ↗VulnCheck XDB
infoleak
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 2
h3x0v3rl0rd/CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗GitHub PoC★ 2
Log4jshell - CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir ↗Exploit-DB
Nettmp NNT 5.1 - SQLi Authentication Bypass
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RIESGO
abrir ↗Exploit-DB
ConnectWise Control 19.2.24707 - Username Enumeration
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RIESGO
abrir ↗Exploit-DB
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip
23RIESGO
abrir ↗Exploit-DB
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir ↗Exploit-DB
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RIESGO
abrir ↗GitHub PoC
alexpena5635/CVE-2021-44228_scanner-main-Modified-
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Exploit-DB
Automox Agent 32 - Local Privilege Escalation
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RIESGO
abrir ↗GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗GitHub PoC
Atmail XSS-CSRF-RCE Exploit Chain
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote atta
23RIESGO
abrir ↗GitHub PoC
Bassmaster Plugin NodeJS RCE
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RIESGO
abrir ↗GitHub PoC
Log4j2 LDAP 취약점 테스트 (CVE-2021-44228)
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls
100RIESGO
abrir ↗GitHub PoC★ 9
darkpills/CVE-2021-25094-tatsu-preauth-rce
Tatsu < 3.3.12 - Unauthenticated RCE
60RIESGO
abrir ↗GitHub PoC
This repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
Presents how to exploit CVE-2021-44228 vulnerability.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗VulnCheck XDB
initial-access
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing
50RIESGO
abrir ↗GitHub PoC★ 4
Auerswald VoIP System Secret Backdoors -PoC
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.