Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.581GitHub PoC 13.708VulnCheck XDB 8225Nuclei 4228Metasploit 3467✓ solo verificadosrecientespopularesriesgo
13.698 exploits
GitHub PoC
LamSonBinh/CVE-2018-20250
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir ↗GitHub PoC
activemq-rce-cve-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗GitHub PoC★ 6
POC for SQLi vulnerability in Icegram express
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir ↗GitHub PoC★ 6
0xr2r/CVE-2024-3400-Palo-Alto-OS-Command-Injection
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗GitHub PoC★ 42
CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗GitHub PoC★ 63
CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗GitHub PoC★ 14
rbih-boulanouar/CVE-2024-4040
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗GitHub PoC★ 4
PoC exploit for GLPI - Command injection using a third-party library script
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir ↗GitHub PoC★ 11
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗GitHub PoC★ 6
Simple honeypot for CVE-2024-3400 Palo Alto PAN-OS Command Injection Vulnerability
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir ↗GitHub PoC
mrrobot0o/CVE-2024-3273-
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC
A basic script that exploits CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC★ 216
Oracle VirtualBox Elevation of Privilege (Local Privilege Escalation) Vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RIESGO
abrir ↗GitHub PoC★ 1
A final project for "Network Security" class at NYCU (National Yang Ming Chiao Tung University, Taiwan). Exploiting a CVE in "EasyAppointments" software.
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RIESGO
abrir ↗GitHub PoC
CVE-2022-24716 (Arbitrary File Disclosure Icingaweb2)
Path traversal in Icinga Web 2
78RIESGO
abrir ↗GitHub PoC★ 6
A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir ↗GitHub PoC
CVE-2023-0386 包含所需运行库
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗GitHub PoC
SOPlanning 1.52.00 CSRF/SQLi/XSS (CVE-2024-33722, CVE-2024-33724)
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
33RIESGO
abrir ↗GitHub PoC
TYuan0816/cve-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir ↗GitHub PoC★ 36
CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC★ 2
JetBrains TeamCity Unauthenticated Remote Code Execution - Python3 Implementation
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗GitHub PoC
bde574786/Sequelize-1day-CVE-2023-25813
SQL Injection via replacements in sequelize
48RIESGO
abrir ↗GitHub PoC★ 2
Python POC for CVE-2023-6019 taken from https://huntr.com/bounties/d0290f3c-b302-4161-89f2-c13bb28b4cfe
Ray Command Injection in cpu_profile Parameter
85RIESGO
abrir ↗GitHub PoC
PoC for CVE-2024-24576 vulnerability "BatBadBut"
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC
Python exploit and checker script for CVE-2024-3400 Palo Alto Command Injection and Arbitrary File Creation
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC★ 1
H3C ER8300G2-X config download
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RIESGO
abrir ↗GitHub PoC
asdfjkl11/CVE-2024-32238
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.