Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
13.654 exploits
GitHub PoC★ 2
CVE-2024-0012批量检测脚本
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir ↗GitHub PoC
My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection
WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
63RIESGO
abrir ↗GitHub PoC
Broken Authentication in Wordpress plugin (Wawp Plugin < 3.0.18)
WordPress Wawp plugin < 3.0.18 - Account Takeover vulnerability
48RIESGO
abrir ↗GitHub PoC★ 1
This is POC of CVE-2024-29671
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code vi
53RIESGO
abrir ↗GitHub PoC★ 2
This tool scans WordPress websites for vulnerabilities in the WP Time Capsule plugin related to CVE-2024-8856. It identifies plugin versions below 1.22.22 as vulnerable and logs results to vuln.txt. Simple and efficient, it helps security researchers and admins detect and address risks quickly.
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗GitHub PoC★ 1
This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific version (`6.0.2.6`) and marks the site as vulnerable if found. The results are saved in a file (`vuln.txt`) for further analysis.
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
48RIESGO
abrir ↗GitHub PoC
POC for CVE-2024-10924 written in Python
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC
FAFAF
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗GitHub PoC★ 1
PANW NGFW CVE-2024-0012
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir ↗GitHub PoC
GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization
GEO my WordPress < 4.4.0.2 - Unauthenticated RCE via LFI
48RIESGO
abrir ↗GitHub PoC
CVE-2024-52316 - Apache Tomcat Authentication Bypass Vulnerability
Apache Tomcat: Authentication bypass when using Jakarta Authentication API
48RIESGO
abrir ↗GitHub PoC
CVE-2023-28354
An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against aff
48RIESGO
abrir ↗GitHub PoC★ 3
Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC
PoC for PAN-OS Exploit
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir ↗GitHub PoC★ 19
Exploits Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924).
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC★ 45
PAN-OS auth bypass + RCE
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir ↗GitHub PoC★ 143
WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler
Windows Task Scheduler Elevation of Privilege Vulnerability
76RIESGO
abrir ↗GitHub PoC
Simple Python script
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC★ 3
Unauthenticated Remote Code Execution via Angular-Base64-Upload Library (npm:bower)
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RIESGO
abrir ↗GitHub PoC★ 20
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir ↗GitHub PoC★ 24
watchtowrlabs/palo-alto-panos-cve-2024-0012
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir ↗GitHub PoC
ubaydev/CVE-2024-10508
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
48RIESGO
abrir ↗GitHub PoC
wudidwo/CVE-2017-12615-poc
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗GitHub PoC★ 8
WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it at your own risk!
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
48RIESGO
abrir ↗GitHub PoC
Andriod binder bug record
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir ↗GitHub PoC★ 2
Vuln disclosure for XOne app
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login
48RIESGO
abrir ↗GitHub PoC★ 2
Relais 2FA <= 1.0 - Authentication Bypass
Relais 2FA <= 1.0 - Authentication Bypass
48RIESGO
abrir ↗GitHub PoC★ 2
WordPress WP Time Capsule Plugin Arbitrary File Upload Vulnerability
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗GitHub PoC★ 1
jesicatjan/WordPress-NotificationX-CVE-2024-1698
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.