Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.814exploits catalogados
32.125CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.248VulnCheck XDB 8150Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
13.235 exploits
GitHub PoC
Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade vers Root (SUID). Ce dépôt contient le rapport technique détaillé, les preuves d'exploitation (PoC) et les mesures de remédiation pour sécuriser l'infrastructure.
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir ↗GitHub PoC
Rishi-kaul/CVE-2025-14847-MongoBleed
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 5
Poc for CVE-2025-7771 to modify PPL Protection
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗GitHub PoC★ 2
nkuty/CVE-2025-54322-exploit
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete
53RIESGO
abrir ↗GitHub PoC★ 1
A new way to exploit CVE-2025-58360 bypass WAF
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir ↗GitHub PoC★ 1
This repository contains a safe Proof of Concept (PoC) to detect vulnerable SmarterMail versions affected by CVE‑2025‑52691. The script performs version detection only and does not exploit the vulnerability.
Upload Arbitrary Files
100RIESGO
abrir ↗GitHub PoC★ 3
An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation, persistence, exfiltration, and interactive mode. For educational and authorized testing only. Credits to the original PoC by yt2w/CVE-2025-52691.
Upload Arbitrary Files
100RIESGO
abrir ↗GitHub PoC
Exploit code for Clinic patient management system v1 unauth rce cpms rce CVE-2022-40471
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
68RIESGO
abrir ↗GitHub PoC
YanC1e/CVE-2025-8191
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir ↗GitHub PoC
This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It demonstrates how the exploit works, including the payload and impact.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
🎯 Automated vulnerability scanner for React2Shell RCE - Google dorking + safe detection for CVE-2025-55182/CVE-2025-66478 (CVSS 10.0)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules
Argument Injection in PHP-CGI
100RIESGO
abrir ↗GitHub PoC
nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗GitHub PoC★ 1
This repo contains my python script version of CVE-2025-14847 (MongoBleed)
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC
Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC
Remake of CVE-2025-14847 MongoDB vulnerability demonstration
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 2
Academic proof-of-concept demonstrating CVE-2025-68645 for authorized security research.
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RIESGO
abrir ↗GitHub PoC
Reproducible Docker lab for CVE-2018-15133 (Laravel Framework token unserialize RCE)
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir ↗GitHub PoC
Context-Aware Memory Leak Scanner & Exploit for CVE-2025-14847.
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2025-14847 (MongoBleed)
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC
MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC
Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 4
Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 13
Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 1
aexdyhaxor/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.