Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.581GitHub PoC 13.708VulnCheck XDB 8225Nuclei 4228Metasploit 3467✓ solo verificadosrecientespopularesriesgo
13.708 exploits
GitHub PoC
FoxyProxys/CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗GitHub PoC
CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML atta
85RIESGO
abrir ↗GitHub PoC
La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y 5.6.1 de la herramienta de compresión XZ.
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC
MAL-004: Command Injection Bypass for CVE-2020-12641 in Roundcube Webmail
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RIESGO
abrir ↗GitHub PoC★ 2
PoC MinIO vulnerability exploit
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗GitHub PoC★ 5
OpenMetadata_RCE (CVE-2024-28255) Batch scan/exploit
Authentication Bypass in OpenMetadata
85RIESGO
abrir ↗GitHub PoC★ 1
Public exploit for CVE-2024-31777
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RIESGO
abrir ↗GitHub PoC★ 1
CVE-2024-24576 PoC for Nim Lang
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 2
0xWhoami35/CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗GitHub PoC★ 50
CVE-2023-6319 proof of concept
Command injection in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service
48RIESGO
abrir ↗GitHub PoC★ 2
adhikara13/CVE-2024-2389
Flowmon Unauthenticated Command Injection Vulnerability
85RIESGO
abrir ↗GitHub PoC★ 5
D-Link NAS Command Execution Exploit
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC★ 9
brains93/CVE-2024-24576-PoC-Python
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 1
Ray OS Command Injection RCE(Unauthorized)
Ray Command Injection in cpu_profile Parameter
85RIESGO
abrir ↗GitHub PoC★ 20
CVE-2024-24576 Proof of Concept
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 59
Example of CVE-2024-24576 use case.
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir ↗GitHub PoC★ 1
The script is from https://github.com/JohnHammond/msdt-follina, just make it simple for me to use it and this script aim at generating the payload for more information refer the johnn hammond link
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 5
A PoC exploit for CVE-2024-3273 - D-Link Remote Code Execution RCE
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC★ 23
CVE-2024-2879 - LayerSlider 7.9.11 - 7.10.0 - Unauthenticated SQL Injection
The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1
68RIESGO
abrir ↗GitHub PoC
CVE-2020-12641: Command Injection via “_im_convert_path” Parameter in Roundcube Webmail
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2021-42013 Vulnerability Scanner This Python script checks for the Remote Code Execution (RCE) vulnerability (CVE-2021-42013) in Apache 2.4.50.
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗GitHub PoC★ 101
D-Link NAS CVE-2024-3273 Exploit Tool
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC★ 13
Exploit for CVE-2024-3273, supports single and multiple hosts
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC
Quick and dirty honeypot for CVE-2024-3273
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir ↗GitHub PoC
Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC
RomainBayle08/CVE-2023-38831
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗GitHub PoC★ 6
An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC
DirtyCOW 笔记
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.