Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.334 exploits
GitHub PoC
调试环境
CVE-2021-44228CRITICALbajo ataqueransomware20 ene 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC198
Proof of concept & details for CVE-2025-21298
CVE-2025-21298CRITICAL20 ene 2025
Windows OLE Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC15
CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.
CVE-2024-43451MEDIUMbajo ataque20 ene 2025
NTLM Hash Disclosure Spoofing Vulnerability
85RIESGO
abrir
GitHub PoC5
A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282, CVE-2023-46805, and CVE-2024-21887.
CVE-2025-0282CRITICALbajo ataqueransomware19 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC5
A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282, CVE-2023-46805, and CVE-2024-21887.
CVE-2024-21887CRITICALbajo ataqueransomware19 ene 2025
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir
GitHub PoC16
Havoc SSRF to RCE
CVE-2024-41570CRITICAL19 ene 2025
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RIESGO
abrir
GitHub PoC3
This is a Chained RCE in the Havoc C2 framework using github.com/chebuya and github.com/IncludeSecurity pocs
CVE-2024-41570CRITICAL19 ene 2025
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RIESGO
abrir
GitHub PoC5
A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282, CVE-2023-46805, and CVE-2024-21887.
CVE-2023-46805HIGHbajo ataqueransomware19 ene 2025
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir
GitHub PoC1
RapidResetClient
CVE-2023-44487HIGHbajo ataque18 ene 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC1
masa42/CVE-2024-38821-POC
CVE-2024-38821CRITICAL18 ene 2025
Authorization Bypass of Static Resources in WebFlux Applications
48RIESGO
abrir
GitHub PoC
PoC: Plugin: Zita Site Builder <= 1.0.2 - Arbitrary Plugin Installation
CVE-2024-54369CRITICAL18 ene 2025
WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
48RIESGO
abrir
GitHub PoC3
Picsmize plugin for WordPress is vulnerable to arbitrary file uploads.
CVE-2024-52380CRITICAL18 ene 2025
WordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
Exploit CVE-2024-54262: Arbitrary File Upload in Import Export for WooCommerce
CVE-2024-54262CRITICAL17 ene 2025
WordPress Import Export For WooCommerce plugin <= 1.6.2 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
This is a repository that aims to provide research material on CVE-2020-14882 as part of a project in partial fullfilment of ACS EDU Program.
CVE-2020-14882CRITICALbajo ataque17 ene 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC15
CVE-2024-57727
CVE-2024-57727CRITICALbajo ataqueransomware17 ene 2025
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RIESGO
abrir
GitHub PoC
c1ph3rbyt3/CVE-2022-29464
CVE-2022-29464CRITICALbajo ataqueransomware17 ene 2025
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC1
c1ph3rbyt3/CVE-2022-24816
CVE-2022-24816CRITICALbajo ataque17 ene 2025
Improper Control of Generation of Code in jai-ext
100RIESGO
abrir
GitHub PoC3
CVE-2024-43468 SCCM SQL Injection Exploit (mTLS unextractable client cert from MacOS keychain version)
CVE-2024-43468CRITICALbajo ataque17 ene 2025
Microsoft Configuration Manager Remote Code Execution Vulnerability
90RIESGO
abrir
GitHub PoC66
watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591
CVE-2024-55591CRITICALbajo ataqueransomware16 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
GitHub PoC1
Palo Alto RCE Vuln
CVE-2024-9474MEDIUMbajo ataqueransomware16 ene 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
GitHub PoC1
Proof of concept for CVE-2022-31814
CVE-2022-31814CRITICAL16 ene 2025
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
GitHub PoC1
A Python tool leveraging Shodan and Scapy to identify and exploit Windows systems vulnerable to CVE-2024-38063, enabling targeted Denial of Service attacks
CVE-2024-38063CRITICAL16 ene 2025
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
This is a Python script PoC for CVE-2019-5029
CVE-2019-5029CRITICAL16 ene 2025
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7
60RIESGO
abrir
GitHub PoC86
Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group
CVE-2022-40684CRITICALbajo ataqueransomware16 ene 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC1
Incorrect Privilege Assignment vulnerability in nssTheme Wp NssUser Register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through 1.0.0.
CVE-2024-54363CRITICAL16 ene 2025
WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerability
48RIESGO
abrir
GitHub PoC31
Ivanti Connect Secure IFT TLS Stack Overflow pre-auth RCE (CVE-2025-0282)
CVE-2025-0282CRITICALbajo ataqueransomware15 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC270
POC exploit for CVE-2024-49138
CVE-2024-49138HIGHbajo ataque15 ene 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC1
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
CVE-2023-46805HIGHbajo ataqueransomware14 ene 2025
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir
GitHub PoC1
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
CVE-2025-0282CRITICALbajo ataqueransomware14 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC1
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
CVE-2024-21887CRITICALbajo ataqueransomware14 ene 2025
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir
anteriorpágina 173 / 445siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.