Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.041exploits catalogados
32.227CVEs con explotación pública
1932probados en laboratorio
13.352 exploits
GitHub PoC1
The EXP/POC of CVE-2019-12725
CVE-2019-1272516 dic 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC
t0mmy4/CVE-2019-12725-modified-exp
CVE-2019-1272516 dic 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC14
A short scraper looking for a POC of CVE-2024-49112
CVE-2024-49112CRITICAL16 dic 2024
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
Rahul-Thakur7/CVE-2023-21554
CVE-2023-21554CRITICAL16 dic 2024
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RIESGO
abrir
GitHub PoC21
LLfam/CVE-2024-1086
CVE-2024-1086HIGHbajo ataqueransomware16 dic 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC
redspy-sec/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware16 dic 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection
CVE-2024-50507CRITICAL16 dic 2024
WordPress DS.DownloadList plugin <= 1.3 - PHP Object Injection vulnerability
48RIESGO
abrir
GitHub PoC3
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised users.
CVE-2021-43798HIGHbajo ataque14 dic 2024
Grafana path traversal
100RIESGO
abrir
GitHub PoC
sudlit/CVE-2023-40028
CVE-2023-40028MEDIUM13 dic 2024
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir
GitHub PoC
tlavi00/CVE-2018-7750
CVE-2018-775013 dic 2024
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RIESGO
abrir
GitHub PoC96
A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code remotely. This vulnerability arises from flaws in the file upload logic, which can be exploited to perform path traversal and malicious file uploads.
CVE-2024-53677CRITICAL13 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC
CVE to CTF FP
CVE-2022-22963CRITICALbajo ataque13 dic 2024
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC4
666asd/CVE-2024-23653
CVE-2024-23653CRITICAL13 dic 2024
BuildKit interactive containers API does not validate entitlements check
48RIESGO
abrir
GitHub PoC
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
CVE-2024-9290CRITICAL13 dic 2024
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
GitHub PoC
Improved version of PikaChu CVE
CVE-2017-12617HIGHbajo ataque13 dic 2024
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC8
CVE-2024-55875 | GHSA-7mj5-hjjj-8rgw | http4k first CVE
CVE-2024-55875CRITICAL13 dic 2024
http4k has a potential XXE (XML External Entity Injection) vulnerability
48RIESGO
abrir
GitHub PoC13
CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system.
CVE-2023-40028MEDIUM12 dic 2024
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir
GitHub PoC
writeup cve-2024-42327
CVE-2024-42327CRITICAL12 dic 2024
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
CVE-2024-10124CRITICAL12 dic 2024
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
60RIESGO
abrir
GitHub PoC9
s2-067(CVE-2024-53677)
CVE-2024-53677CRITICAL12 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC4
exploit CVE-2024-38475(mod_rewrite weakness with filesystem path matching)
CVE-2024-38475CRITICALbajo ataque12 dic 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RIESGO
abrir
GitHub PoC
This repo contains both the exploit and the explaination of how this vulnerability is exploited
CVE-2019-1863411 dic 2024
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC25
Cleo Unrestricted file upload and download PoC (CVE-2024-50623)
CVE-2024-50623CRITICALbajo ataqueransomware11 dic 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RIESGO
abrir
GitHub PoC8
This PoC is targeting vulnerabilities in Palo Alto PAN-OS, specifically CVE-2024-0012 and CVE-2024-9474. This script automates the exploitation process, including payload creation, chunked delivery, and seamless command execution.
CVE-2024-0012CRITICALbajo ataqueransomware11 dic 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC2
Palo Alto Networks PAN-OS(CVE-2024-9474) POC
CVE-2024-9474MEDIUMbajo ataqueransomware11 dic 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
GitHub PoC1
KiviCare – Clinic & Patient Management System (EHR) WordPress Plugin Unauthenticated SQL Injection PoC
CVE-2024-11728HIGH11 dic 2024
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection
61RIESGO
abrir
GitHub PoC
itform-fr/Zabbix---CVE-2024-42327
CVE-2024-42327CRITICAL11 dic 2024
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC
Cái này dựng lên với mục đích cho ae tham khảo, chê thì đừng có xem. :))))
CVE-2023-346011 dic 2024
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
GitHub PoC
An example of a repo that would make use of the CVE-2024-32002
CVE-2024-32002CRITICAL11 dic 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
CVE-2024-55557
CVE-2024-55557CRITICAL10 dic 2024
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti
48RIESGO
abrir
anteriorpágina 178 / 446siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.