Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8811Nuclei 4349Metasploit 3488✓ solo verificadosrecientespopularesriesgo
78.258 exploits
GitHub PoC★ 21
Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗VulnCheck XDB
infoleak
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗GitHub PoC★ 1
Another implementation for linux privilege escalation exploit via snap(d) (CVE-2019-7304)
Local privilege escalation via snapd socket
53RIESGO
abrir ↗GitHub PoC★ 38
CVE-2021-22192 靶场: 未授权用户 RCE 漏洞
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
53RIESGO
abrir ↗GitHub PoC★ 8
F5 BIG-IP远程代码执行;cve-2021-22986,批量检测;命令执行利用
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir ↗VulnCheck XDB
initial-access
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir ↗GitHub PoC
siramk/CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir ↗VulnCheck XDB
initial-access
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir ↗Exploit-DB
Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RIESGO
abrir ↗GitHub PoC★ 10
Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RIESGO
abrir ↗GitHub PoC★ 1
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗VulnCheck XDB
initial-access
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir ↗Exploit-DB
Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio
28RIESGO
abrir ↗GitHub PoC★ 33
Vulnerability analysis and PoC for the Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (RCE)
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir ↗GitHub PoC
Proof of concept for CVE-2020-11819 and CVE-2020-15946
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RIESGO
abrir ↗Metasploit0
macOS Gatekeeper check bypass
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2
90RIESGO
abrir ↗Metasploit0
macOS Gatekeeper check bypass
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey
18RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 10
CVE-2017-0100、MS17-012、Eop
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RIESGO
abrir ↗GitHub PoC★ 52
Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2021-22986 Checker Script in Python3
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RIESGO
abrir ↗VulnCheck XDB
initial-access
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir ↗Exploit-DB
MyBB 1.8.25 - Poll Vote Count SQL Injection
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RIESGO
abrir ↗GitHub PoC
analytics ProxyLogo Mail exchange RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.