Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
77.900 exploits
VulnCheck XDB
initial-access
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RIESGO
abrir ↗Exploit-DB
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RIESGO
abrir ↗Exploit-DB
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RIESGO
abrir ↗Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listi
28RIESGO
abrir ↗GitHub PoC★ 1
Lab setup for CVE-2021-41773 (Apache httpd 2.4.49) and CVE-2021-42013 (Apache httpd 2.4.50).
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 17
CVE-2021-36260
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RIESGO
abrir ↗VulnCheck XDB
initial-access
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗GitHub PoC★ 3
Dahua IPC/VTH/VTO devices auth bypass exploit
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir ↗GitHub PoC★ 1
Exploit For CVE-2019-17662
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗GitHub PoC★ 11
Scanner for CVE-2022-22948 an Information Disclosure in VMWare vCenter
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RIESGO
abrir ↗GitHub PoC★ 35
Little thing put together quickly to demonstrate this CVE
jQuery has a potential XSS vulnerability
55RIESGO
abrir ↗GitHub PoC★ 478
Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC
TIC4301 Project - CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 2
Simple honeypot for CVE-2021-41773 vulnerability
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗VulnCheck XDB
initial-access
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 5
The first vulnerability with the CVE identifier CVE-2021-41773 is a path traversal flaw that exists in Apache HTTP Server 2.4.49.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
CVE-2020-25078账号密码信息泄露批量脚本Batch script of D-Link DCS series camera account password information disclosure
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir ↗GitHub PoC
metehangenel/MSHTML-CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RIESGO
abrir ↗Exploit-DB
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.