Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8216Nuclei 4223Metasploit 3464✓ solo verificadosrecientespopularesriesgo
13.668 exploits
GitHub PoC★ 1
CVE-2024-41651
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func
48RIESGO
abrir ↗GitHub PoC
bolkv/CVE-2024-4320
Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui
60RIESGO
abrir ↗GitHub PoC★ 2
exploit que vulnera Jenkins hecho en Python
ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
48RIESGO
abrir ↗GitHub PoC★ 49
Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗GitHub PoC★ 1
An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗GitHub PoC
This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack. It provides information on the vulnerable code, recommended fixes, and how to extract and decrypt administrative credentials.
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action
48RIESGO
abrir ↗GitHub PoC★ 6
CVE-2024-32113 Apache OFBIZ Batch Scanning
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir ↗GitHub PoC
VanishedPeople/CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗GitHub PoC★ 1
Found this on exploit-db, decided to make my own for practice. This exploit will search out the passwd file and print the contents on a vulnerable system.
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RIESGO
abrir ↗GitHub PoC★ 1
This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC★ 6
Calibre 远程代码执行(CVE-2024-6782)Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
Calibre Remote Code Execution
85RIESGO
abrir ↗GitHub PoC★ 1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗GitHub PoC
Abdurahmon3236/CVE-2024-36539
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t
48RIESGO
abrir ↗GitHub PoC
Abdurahmon3236/CVE-2024-6366
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RIESGO
abrir ↗GitHub PoC★ 2
A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC
nastar-id/CVE-2024-32700
WordPress Kognetiks Chatbot for WordPress plugin <= 2.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗GitHub PoC
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC★ 1
Proof of concept exploit for CVE-2021-21551
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir ↗GitHub PoC
adapting CVE-2024-32002 for running offline and locally
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗GitHub PoC
Abdurahmon3236/CVE-2024-40110
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability
48RIESGO
abrir ↗GitHub PoC★ 2
Vulnerability Scanner for CVE-2024-37085 and Exploits ( For Educational Purpose only)
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RIESGO
abrir ↗GitHub PoC
y1s4s/CVE-2024-36401-PoC
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗GitHub PoC
Exploit script for CVE-2022-41544 in GetSimple CMS, with enhanced error handling and detailed usage instructions.
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
41RIESGO
abrir ↗GitHub PoC★ 1
An exploit for CVE-2024-6387, targeting a signal handler race condition in OpenSSH's server
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC★ 1
bananoname/cve-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗GitHub PoC★ 12
Proof of concept python script for regreSSHion exploit.
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.