Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
13.736 exploits
GitHub PoC★ 1
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2022-46169). Run it at your own risk!
Unauthenticated Command Injection
100RIESGO
abrir ↗GitHub PoC
lionelmusonza/CVE-2023-26866
GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respe
48RIESGO
abrir ↗GitHub PoC★ 3
CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC
webmin <=1.920 - RCE via command injection vulnerability
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗GitHub PoC★ 1
ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RIESGO
abrir ↗GitHub PoC
turnernator1/Node.js-CVE-2017-5941
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RIESGO
abrir ↗GitHub PoC
jacquesquail/CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 10
CVE-2023-28432 MinIO敏感信息泄露检测脚本
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗GitHub PoC
0759104103/cd-CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗GitHub PoC★ 1
Full LPE Exploit for CVE-2019-5596 / FreeBSD-SA-19:02.fd
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RIESGO
abrir ↗GitHub PoC
cyberdesu/Remote-Buffer-overflow-CVE-2003-0172
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote at
28RIESGO
abrir ↗GitHub PoC★ 3
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Path traversal in Icinga Web 2
78RIESGO
abrir ↗GitHub PoC
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RIESGO
abrir ↗GitHub PoC
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RIESGO
abrir ↗GitHub PoC★ 319
EXP for CVE-2023-28434 MinIO unauthorized to RCE
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RIESGO
abrir ↗GitHub PoC★ 2
通过vulhub的复现过程实现了,基本的批量检测。比较垃圾但是勉强能用
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗GitHub PoC★ 3
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir ↗GitHub PoC★ 1
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir ↗GitHub PoC★ 1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 5
0xNahim/CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗GitHub PoC★ 3
Unauthenticated RCE in Open Web Analytics version <1.7.4
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir ↗GitHub PoC★ 4
Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Arbitrary code execution for authenticated users in Icinga Web 2
46RIESGO
abrir ↗GitHub PoC★ 1
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir ↗GitHub PoC
Brandaoo/CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC★ 1
RSA NetWitness Platform EDR Agent / Incorrect Access Control - Code Execution
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RIESGO
abrir ↗GitHub PoC★ 1
An exploitation demo of Outlook Elevation of Privilege Vulnerability
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC
CVE-2023-23397 powershell patch script for Windows 10 and 11
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.