Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8773Nuclei 4340Metasploit 3485✓ solo verificadosrecientespopularesriesgo
78.149 exploits
GitHub PoC★ 2
CVE-2021-21985 Checker.
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir ↗GitHub PoC
This script check the CVE-2021-21985 vulnerability and patch on vCenter Server.
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir ↗GitHub PoC★ 3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RIESGO
abrir ↗GitHub PoC
rnnsz/CVE-2008-4654
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗GitHub PoC★ 226
PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.
Windows Hyper-V Remote Code Execution Vulnerability
60RIESGO
abrir ↗GitHub PoC★ 3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗GitHub PoC
rnnsz/CVE-2017-15950
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RIESGO
abrir ↗GitHub PoC
JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab.
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir ↗GitHub PoC★ 59
arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir ↗GitHub PoC★ 213
alt3kx/CVE-2021-21985_PoC
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir ↗GitHub PoC★ 1
Script to patch your domain computers about the CVE-2021-21551. Privesc on machines that have the driver dbutil_2_3.sys, installed by some DELL tools (BIOS updater, SupportAssist...)
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)
LifterLMS < 4.21.1 - Authenticated Stored XSS in Edit Profile
23RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir ↗GitHub PoC
Proof of Concept for CVE-2020-14295.
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir ↗Exploit-DB
Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated)
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php
50RIESGO
abrir ↗Exploit-DB
Trixbox 2.8.0.4 - 'lang' Path Traversal
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter
50RIESGO
abrir ↗GitHub PoC★ 1
Cacti v1.2.8 Unauthenticated Remote Code Execution
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPFusion 9.03.50 - Remote Code Execution
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RIESGO
abrir ↗GitHub PoC★ 3
My notes for CVE-2004-1561 IceCast exploitation
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir ↗GitHub PoC
Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team)
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir ↗Metasploit300
Squid Proxy Range Header DoS
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a
40RIESGO
abrir ↗Metasploit300
Squid Proxy Range Header DoS
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to
23RIESGO
abrir ↗GitHub PoC★ 1
Multiple vulnerabilities in the vSphere Client (HTML5) were privately reported to VMware. Updates and workarounds are available to address these vulnerabilities in affected VMware products.
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir ↗GitHub PoC
ykg88/OHTS_IE6052-CVE-2020-17087
Windows Kernel Local Elevation of Privilege Vulnerability
71RIESGO
abrir ↗VulnCheck XDB
initial-access
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.