Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
13.743 exploits
GitHub PoC★ 7
The manage engine mass loader for CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir ↗GitHub PoC★ 28
Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir ↗GitHub PoC
it is the official Fix of Wordpress CVE-2018-6389.
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 6
Python exploit for RCE in Wordpress
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir ↗GitHub PoC★ 165
A script to automate privilege escalation with CVE-2023-22809 vulnerability
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗GitHub PoC★ 1
Demo webapp vulnerable to CVE-2022-44900
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea
48RIESGO
abrir ↗GitHub PoC★ 4
Remote Code Execution in Social Warfare Plugin before 3.5.3 for Wordpress.
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir ↗GitHub PoC
PoC for cve-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir ↗GitHub PoC★ 2
A POC on how to exploit CVE-2022-27518
Unauthenticated remote arbitrary code execution
78RIESGO
abrir ↗GitHub PoC★ 129
POC for CVE-2022-47966 affecting multiple ManageEngine products
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir ↗GitHub PoC★ 1
test for the ioc described for FG-IR-22-398
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir ↗GitHub PoC
Project for the Cyberspace Security class.
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗GitHub PoC★ 2
CVE-2014-5460
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RIESGO
abrir ↗GitHub PoC
notareaperbutDR34P3r/CVE-2022-40684-Rust
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir ↗GitHub PoC
Exploit For OverlayFS
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir ↗GitHub PoC★ 2
Cacti: Unauthenticated Remote Code Execution Exploit in Ruby
Unauthenticated Command Injection
100RIESGO
abrir ↗GitHub PoC★ 2
cbk914/CVE-2022-30525_check
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir ↗GitHub PoC
nhamle2/CVE-2015-8660
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir ↗GitHub PoC★ 3
cbk914/CVE-2022-26134_check
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗GitHub PoC★ 4
iliass-dahman/CVE-2022-22963-POC
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir ↗GitHub PoC★ 6
Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.
SQL injection in WordPress
78RIESGO
abrir ↗GitHub PoC★ 1
CVE 2022-45299
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi
48RIESGO
abrir ↗GitHub PoC★ 9
Exploit to CVE-2022-46169 vulnerability
Unauthenticated Command Injection
100RIESGO
abrir ↗GitHub PoC★ 2
cve-2010-1622 Learning Environment
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RIESGO
abrir ↗GitHub PoC★ 326
Wh04m1001/CVE-2023-21752
Windows Backup Service Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC
CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir ↗GitHub PoC
zabbix saml bypass
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir ↗GitHub PoC★ 28
CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad
Code Injection in pyload/pyload
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.