Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.334 exploits
GitHub PoC
Alienfader/CVE-2020-29607
CVE-2020-2960711 feb 2025
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir
GitHub PoC1
yenyangmjaze/cve-2024-10914
CVE-2024-10914CRITICAL11 feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC2
demonstriert, wie mittels missbräuchlicher Nutzung eines Swap-Cookies eine VPN-Session übernommen werden kann. Wichtig: Dieses Projekt dient ausschliesslich zu Bildungs- und Forschungszwecken – bitte nur in Umgebungen verwenden, in denen Du explizit authorisiert bist.
CVE-2024-53704HIGHbajo ataqueransomware11 feb 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir
GitHub PoC
Yami0x777/Belsen_Group-et-exploitation-de-la-CVE-2022-40684
CVE-2022-40684CRITICALbajo ataqueransomware10 feb 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC1
cve-2019-5420 POC simple ruby script
CVE-2019-542010 feb 2025
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
GitHub PoC
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
CVE-2024-27348CRITICALbajo ataque10 feb 2025
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
GitHub PoC
skrkcb2/CVE-2024-5452
CVE-2024-5452CRITICAL09 feb 2025
RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
53RIESGO
abrir
GitHub PoC1
SSHEnum es una herramienta de enumeración de usuarios SSH basada en CVE-2018-15473. Permite detectar usuarios válidos aprovechando respuestas diferenciadas del servidor. Es rápida, compatible con Python 3.12 y soporta wordlists. Uso exclusivo para auditoría y pruebas de seguridad autorizadas.
CVE-2018-15473MEDIUM09 feb 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
0x7556/CVE-2024-55591
CVE-2024-55591CRITICALbajo ataqueransomware09 feb 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
GitHub PoC
RogelioPumajulca/CVE-2022-0847
CVE-2022-0847HIGHbajo ataque09 feb 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
pz-frontend-manager < 1.0.6 - CSRF Profile Picture Exploit
CVE-2024-6244HIGH08 feb 2025
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RIESGO
abrir
GitHub PoC
This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege escalation on Ubuntu 20.04 with sudo version 1.8.31 and glibc version 2.31. It includes an assembly-based exploit, a shared object payload, and a Makefile for automated compilation.
CVE-2021-3156HIGHbajo ataque08 feb 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC4
Cityworks deserialization of untrusted data vulnerability Detection
CVE-2025-0994HIGHbajo ataque07 feb 2025
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to
83RIESGO
abrir
GitHub PoC3
Snizi/Moodle-CVE-2024-43425-Exploit
CVE-2024-43425HIGH07 feb 2025
Moodle: remote code execution via calculated question types
78RIESGO
abrir
GitHub PoC
PoC of CVE-2022-30190
CVE-2022-30190HIGHbajo ataqueransomware07 feb 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Directory Traversal Exploit written in Bash for NVMS-1000 (CVE-2019-20085).
CVE-2019-20085HIGHbajo ataque06 feb 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
GitHub PoC1
This is a Python script that exploits the CVE-2024-6624 vulnerability in the JSON API User <= 3.9.3 plugin for WordPress.
CVE-2024-6624CRITICAL06 feb 2025
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RIESGO
abrir
GitHub PoC4
Python script for CVE-2024-0012 / CVE-2024-9474 exploit
CVE-2024-0012CRITICALbajo ataqueransomware06 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC
KGorbakon/CVE-2023-41425
CVE-2023-41425MEDIUM05 feb 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
GitHub PoC
Arthikw3b/RCE-CVE-2024-7954
CVE-2024-7954CRITICAL05 feb 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
GitHub PoC
cy3erdr4g0n/CVE-2024-10924
CVE-2024-10924CRITICAL05 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC1
SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]
CVE-2024-24919HIGHbajo ataqueransomware05 feb 2025
Information disclosure
100RIESGO
abrir
GitHub PoC
daikinitanda/-CVE-2024-47875-
CVE-2024-47875CRITICAL05 feb 2025
DOMPurify nesting-based mXSS
48RIESGO
abrir
GitHub PoC1
qw3rtyou/CVE-2021-44228_dockernize
CVE-2021-44228CRITICALbajo ataqueransomware04 feb 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
CVE-2019-2215 poc for Huawei hardened kernel
CVE-2019-2215HIGHbajo ataque04 feb 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC
In this challenge, I analyzed the Spring4Shell (CVE-2022-22965) vulnerability, investigated security bypasses, and wrote an Incident Postmortem Report detailing the detection, impact, and resolution of the attack. I also implemented a firewall rule in Python to block malicious requests and prevent future exploitation.
CVE-2022-22965CRITICALbajo ataque03 feb 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.
CVE-2017-0144HIGHbajo ataqueransomware03 feb 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
Code to decrypt Huawei passwords CVE-2012-4960
CVE-2012-496003 feb 2025
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605
23RIESGO
abrir
GitHub PoC
CVE-2017-8869 - MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
CVE-2017-886902 feb 2025
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir
GitHub PoC
This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in Academy for Module "Attacking Commoon Applications" and section "Attacking Drupal".
CVE-2014-370402 feb 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
anteriorpágina 170 / 445siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.