Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
79.107 exploits
GitHub PoC★ 9
CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗GitHub PoC★ 162
NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir ↗GitHub PoC★ 14
Script that checks if the system is vulnerable to CVE-2020-0796 (SMB v3.1.1)
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗GitHub PoC★ 18
Weaponized PoC for SMBv3 TCP codec/compression vulnerability
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Exploit-DB
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nagios XI - Authenticated Remote Command Execution (Metasploit)
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir ↗GitHub PoC★ 14
CVE-2020-2555
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir ↗Metasploit600
Background Intelligent Transfer Service Arbitrary File Move Privilege Elevation Vulnerability
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir ↗Metasploit300
CVE-2020-1170 Cloud Filter Arbitrary File Creation EOP
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome 67_ 68 and 69 - Object.create Type Confusion (Metasploit)
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RIESGO
abrir ↗GitHub PoC★ 1
exploit for sudo CVE-2019-18634
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir ↗Metasploit600
Pandora FMS Ping Authenticated Remote Code Execution
Pandora FMS Authenticated Remote Code Execution via Ping Module
36RIESGO
abrir ↗GitHub PoC★ 13
PoC of CVE-2019-15126 kr00k vulnerability
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-FPM - Underflow Remote Code Execution (Metasploit)
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir ↗VulnCheck XDB
infoleak
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗GitHub PoC★ 1
Gather a list of Citrix appliances in a country / state pair, and check if they're vulnerable to CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗GitHub PoC★ 177
Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir ↗GitHub PoC
simple poc for CVE-2020-0069
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RIESGO
abrir ↗GitHub PoC★ 47
CVE-2020-8597 pppd buffer overflow poc
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗VulnCheck XDB
client-side
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.
28RIESGO
abrir ↗GitHub PoC★ 6
A CVE-2019-11580 shell
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RIESGO
abrir ↗GitHub PoC
CVE-2020-8597
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.