Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.581GitHub PoC 13.708VulnCheck XDB 8225Nuclei 4228Metasploit 3467✓ solo verificadosrecientespopularesriesgo
13.689 exploits
GitHub PoC★ 2
A proof of concept for the git vulnerability CVE-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗GitHub PoC★ 18
Hook for the PoC for exploiting CVE-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗GitHub PoC
svchostmm/CVE-2024-25600-mass
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗GitHub PoC★ 27
CVE-2023-34992: Fortinet FortiSIEM Command Injection Proof of Concept Exploit
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RIESGO
abrir ↗GitHub PoC★ 5
CVE-2024-29895 | RCE on CACTI 1.3.X dev
Cacti command injection in cmd_realtime.php
85RIESGO
abrir ↗GitHub PoC
10cks/CVE-2024-21111-del
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RIESGO
abrir ↗GitHub PoC★ 78
CVE-2024-32640 | Automated SQLi Exploitation PoC
MasaCMS SQL Injection vulnerability
85RIESGO
abrir ↗GitHub PoC★ 13
Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC
Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and https://github.com/ly4k/CurveBall
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir ↗GitHub PoC
CVE-2016-10033 Wordpress 4.6 Exploit
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2021-34646
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2018-14716
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques
35RIESGO
abrir ↗GitHub PoC★ 23
CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds
Cacti command injection in cmd_realtime.php
85RIESGO
abrir ↗GitHub PoC
W3BW/CVE-2024-27956-RCE-File-Package
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir ↗GitHub PoC★ 5
jakabakos/CVE-2023-26360-adobe-coldfusion-rce-exploit
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir ↗GitHub PoC★ 15
aelmokhtar/CVE-2024-34716
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RIESGO
abrir ↗GitHub PoC★ 4
High CVE-2024-4761 Exploit
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds
76RIESGO
abrir ↗GitHub PoC
CVE-2024-34832
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a craf
48RIESGO
abrir ↗GitHub PoC★ 2
Checker for CVE-2021-3156 with static version check
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC★ 2
POC for CVE-2024-4701
Path Traversal vulnerability via File Uploads in Genie
53RIESGO
abrir ↗GitHub PoC★ 1
Updated python3 exploit for CVE-2018-10583 (LibreOffice/Open Office - '.odt' Information Disclosure )
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RIESGO
abrir ↗GitHub PoC
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗GitHub PoC
andrelia-hacks/CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC★ 7
Kernel Exploit for CVE-2016-6187 (Local Privilege Escalation)
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RIESGO
abrir ↗GitHub PoC★ 1
Tool for finding CVE-2023-27524 (Apache Superset - Authentication Bypass)
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗GitHub PoC★ 2
Apache Superset - Authentication Bypass
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗GitHub PoC
th3Hellion/CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.