Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
13.618 exploits
GitHub PoC12
math-x-io/CVE-2024-54152-poc
CVE-2024-54152CRITICAL30 dic 2024
Angular Expressions - Remote Code Execution when using locals
48RIESGO
abrir
GitHub PoC4
AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF challenges. Strictly for authorized and educational use only!
CVE-2017-0144HIGHbajo ataqueransomware30 dic 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
luongchivi/Preproduce-CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware30 dic 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
PoC for CVE-2024-21182
CVE-2024-21182HIGHbajo ataque29 dic 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RIESGO
abrir
GitHub PoC2
PoC for CVE-2024-21182
CVE-2024-21182HIGHbajo ataque29 dic 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RIESGO
abrir
GitHub PoC2
Hi this is a revised and enhanced code for CVE-2019-0232
CVE-2019-023229 dic 2024
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC1
CVE-2024-50379-exp
CVE-2024-50379CRITICAL28 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC
Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE
CVE-2024-8069MEDIUMbajo ataque28 dic 2024
Limited remote code execution with privilege of a NetworkService Account access
68RIESGO
abrir
GitHub PoC
A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability and perform unauthorized domain controller access.
CVE-2020-1472MEDIUMbajo ataqueransomware28 dic 2024
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC2
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. (CRITICAL)
CVE-2024-7954CRITICAL28 dic 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
GitHub PoC1
Nxploited/CVE-2024-9234
CVE-2024-9234CRITICAL28 dic 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC3
CVE-2023-40028 PoC Exploit
CVE-2023-40028MEDIUM28 dic 2024
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir
GitHub PoC
Nxploited/CVE-2024-9933
CVE-2024-9933CRITICAL27 dic 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RIESGO
abrir
GitHub PoC
Malware Analysis CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware26 dic 2024
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC
Testing the latset Apache Tomcat CVE-2024-50379 Vuln
CVE-2024-50379CRITICAL26 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC
AleksaZatezalo/CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque26 dic 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC2
Drupal CVE-2024-45440
CVE-2024-45440MEDIUM26 dic 2024
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash
48RIESGO
abrir
GitHub PoC
yoohhuu/Rocket-Chat-3.12.1-PoC-CVE-2021-22911-
CVE-2021-2291126 dic 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC
A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1
CVE-2024-23334MEDIUM25 dic 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC5
WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本
CVE-2024-9047CRITICAL25 dic 2024
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RIESGO
abrir
GitHub PoC4
This repository contains a Python script designed to exploit CVE-2024-50379, a vulnerability that allows attackers to upload a JSP shell to a vulnerable server and execute arbitrary commands remotely. This exploit is particularly useful when the /uploads directory is either unprotected or not present on the target server.
CVE-2024-50379CRITICAL25 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC1
UnionTech-Software/libtheora-CVE-2024-56431-PoC
CVE-2024-56431CRITICAL25 dic 2024
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: th
48RIESGO
abrir
GitHub PoC
A PoC exploit for CVE-2024-10914 - D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL24 dic 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC1
The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload.
CVE-2024-9290CRITICAL24 dic 2024
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
GitHub PoC3
Unauthenticated Local File Inclusion
CVE-2024-12209CRITICAL24 dic 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RIESGO
abrir
GitHub PoC1
CVE-2024-50379利用
CVE-2024-50379CRITICAL23 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC
hiteshpatra/CVE-2024-53677
CVE-2024-53677CRITICAL23 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC83
tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp
CVE-2024-50379CRITICAL23 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC7
CVE-2024-50623 POC - Cleo Unrestricted file upload and download
CVE-2024-50623CRITICALbajo ataqueransomware23 dic 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RIESGO
abrir
GitHub PoC4
CVE-2024-56145 SSTI to RCE - twig templates
CVE-2024-56145CRITICALbajo ataque22 dic 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
anteriorpágina 184 / 454siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.