Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.295exploits catalogados
36.048CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.464VulnCheck XDB 8813Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
78.295 exploits
GitHub PoC
Rust implementation of CVE-2018-16763 with some extra features.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗GitHub PoC
1nteger-c/CVE-2019-8605
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RIESGO
abrir ↗Metasploit600
Lucee Administrator imgProcess.cfm Arbitrary File Write
Remote Code Exploit in Lucee Admin
78RIESGO
abrir ↗VulnCheck XDB
local
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RIESGO
abrir ↗GitHub PoC★ 18
Exploit script for CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir ↗VulnCheck XDB
initial-access
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir ↗GitHub PoC
CVE-2020-17519 EXP
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗Exploit-DB
Laravel 8.4.2 debug mode - Remote code execution
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗Exploit-DB
Nagios XI 5.7.X - Remote Code Execution RCE (Authenticated)
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir ↗GitHub PoC★ 82
PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir ↗GitHub PoC★ 289
Exploit for CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗Metasploit600
Unauthenticated remote code execution in Ignition
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗GitHub PoC
Starry-lord/CVE-2018-0114
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir ↗VulnCheck XDB
initial-access
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2017-12615 任意文件写入exp,写入webshell
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
48RIESGO
abrir ↗Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
Microsoft Exchange Remote Code Execution Vulnerability
65RIESGO
abrir ↗GitHub PoC
AnasTaoutaou/CVE-2019-5420
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Flink directory traversal attack: remote file writing through the REST API
50RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Flink directory traversal attack: remote file writing through the REST API
50RIESGO
abrir ↗VulnCheck XDB
infoleak
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗GitHub PoC★ 8
[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗GitHub PoC★ 5
ElmouradiAmine/CVE-2020-7048
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any
53RIESGO
abrir ↗GitHub PoC
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.