Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8216Nuclei 4223Metasploit 3464✓ solo verificadosrecientespopularesriesgo
13.654 exploits
GitHub PoC★ 7
potential memory corruption vulnerabilities in IPv6 networks.
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 4
Windows TCP/IP IPv6(CVE-2024-38063)
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 3
Apache OFBiz CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗GitHub PoC
Apache: a Mainstream Web Service Turned a Vector of Attack for Remote Code Execution
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 2
D0rDa4aN919/CVE-2023-22809-Exploiter
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗GitHub PoC★ 1
【Teedy 1.11】Account Takeover via XSS
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
41RIESGO
abrir ↗GitHub PoC★ 2
This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC★ 6
This exploit will attempt to execute system commands on SPIP targets.
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir ↗GitHub PoC★ 4
Jelly Template Injection Vulnerability in ServiceNow | POC CVE-2024-4879
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗GitHub PoC★ 20
patchpoint/CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC
zxybfq/CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗GitHub PoC★ 10
CVE-2024-25641 - RCE Automated Exploit - Cacti 1.2.26
Cacti RCE vulnerability when importing packages
85RIESGO
abrir ↗GitHub PoC★ 1
Nuclei template to scan for Apache Ofbiz affecting versions before 18.12.15
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗GitHub PoC★ 2
PoC for CVE-2024-25641 Authenticated RCE on Cacti v1.2.26
Cacti RCE vulnerability when importing packages
85RIESGO
abrir ↗GitHub PoC★ 7
PoC for the CVE-2024 Litespeed Cache Privilege Escalation
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗GitHub PoC★ 4
Mass scanner for CVE-2024-36401
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗GitHub PoC
CVE-2023-4220 Chamilo Exploit
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC
sanan2004/CVE-2023-20198
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗GitHub PoC
CVE-2024-45265
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to exe
48RIESGO
abrir ↗GitHub PoC★ 8
This repository automates the process of exploiting CVE-2024-25641 on Cacti 1.2.26
Cacti RCE vulnerability when importing packages
85RIESGO
abrir ↗GitHub PoC★ 2
Apache-HTTP-Server-2.4.50-RCE This tool is designed to test Apache servers for the CVE-2021-41773 / CVE-2021-42013 vulnerability. It is intended for educational purposes only and should be used responsibly on systems you have explicit permission to test.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
POC & Lab For CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
Sudo Privilege Escalation: CVE-2023-22809 Simulation This project simulates the Sudo privilege escalation vulnerability (CVE-2023-22809) to demonstrate how unauthorized root access can be gained. It involves identifying and exploiting this vulnerability in a controlled environment using Parrot OS, the Sudo command, and Bash scripting.
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗GitHub PoC
RCE OpenSSH CVE-2024-6387 Check and Exploit
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC★ 2
Modified for GLPI Offsec Lab: call_user_func, array_map, passthru
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir ↗GitHub PoC★ 5
LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗GitHub PoC★ 77
GiveWP PHP Object Injection exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir ↗GitHub PoC★ 1
Kernel exploit for Xbox SystemOS using CVE-2024-30088
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir ↗GitHub PoC★ 3
Telerik Report Server deserialization and authentication bypass exploit chain for CVE-2024-4358/CVE-2024-1800
Registration Authentication Bypass Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.