Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.305 exploits
GitHub PoC★ 2
A proof of concept for ReadyAPI 2.5.0/2.6.0 Remote Code Execution Vulnerability.
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
23RIESGO
abrir ↗Exploit-DB
Zotonic < 0.47.0 mod_admin - Cross-Site Scripting
Zotonic before version 0.47 has mod_admin XSS.
23RIESGO
abrir ↗GitHub PoC★ 1
davidmthomsen/CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ruby On Rails - DoubleTap Development Mode secret_key_base Remote Code Execution (Metasploit)
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir ↗GitHub PoC★ 4
WordPress crop-image exploitation
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RIESGO
abrir ↗Exploit-DB
CentOS Web Panel 0.9.8.793 (Free) / v0.9.8.753 (Pro) / 0.9.8.807 (Pro) - Domain Field (Add DNS Zone) Cross-Site Scripting
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro)
23RIESGO
abrir ↗GitHub PoC★ 21
lasensio/cve-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pimcore < 5.71 - Unserialize Remote Code Execution (Metasploit)
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RIESGO
abrir ↗Exploit-DB
Intelbras IWR 3000N - Denial of Service (Remote Reboot)
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Domoticz 4.10577 - Unauthenticated Remote Command Execution
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux - Missing Locking Between ELF coredump code and userfaultfd VMA Modification
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RIESGO
abrir ↗GitHub PoC★ 1
PoC command injection example for cve-2018-1002105 based off https://github.com/gravitational/cve-2018-1002105
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Domoticz 4.10577 - Unauthenticated Remote Command Execution
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
28RIESGO
abrir ↗Metasploit600
Barco WePresent file_transfer.cgi Command Injection
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir ↗Exploit-DB
Spring Cloud Config 2.1.x - Path Traversal (Metasploit)
Directory Traversal with spring-cloud-config-server
60RIESGO
abrir ↗Exploit-DB
Intelbras IWR 3000N 1.5.0 - Cross-Site Request Forgery
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RIESGO
abrir ↗Exploit-DB
HumHub 1.3.12 - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HT
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AIS logistics ESEL-Server - Unauthenticated SQL Injection Remote Code Execution (Metasploit)
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app)
50RIESGO
abrir ↗Exploit-DB
Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir ↗GitHub PoC★ 58
Spring Data Commons RCE 远程命令执行漏洞
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir ↗Metasploit600
GetSimpleCMS Unauthenticated RCE
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
60RIESGO
abrir ↗GitHub PoC
Confluence Widget Connector path traversal (CVE-2019-3396)
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir ↗GitHub PoC
shawntns/exploit-CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC
An intentionally vulnerable (CVE-2017-8046) SrpingData REST appl with Swagger Support for pentesting purposes
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.