Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
13.618 exploits
GitHub PoC1
CVE-2024-55557
CVE-2024-55557CRITICAL10 dic 2024
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti
48RIESGO
abrir
GitHub PoC
This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)
CVE-2024-23346CRITICAL09 dic 2024
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir
GitHub PoC
Danyw24/CVE-2004-1561-Icecast-Header-Overwrite-buffer-overflow-RCE-2.0.1-Win32-
CVE-2004-156109 dic 2024
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
GitHub PoC
A simple python script to test for CVE-2024-9441.
CVE-2024-9441CRITICAL09 dic 2024
Linear eMerge e3-Series Forgot Password Command Injection
60RIESGO
abrir
GitHub PoC
Jimmy01240397/CVE-2012-1823-Analyze
CVE-2012-1823CRITICALbajo ataque09 dic 2024
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC1
This repository is a proof of concept (POC) for CVE-2024-23334, demonstrating an attempt to replicate the bug in aiohttp that leads to Local File Inclusion (LFI).
CVE-2024-23334MEDIUM09 dic 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC1
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
CVE-2024-12209CRITICAL09 dic 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RIESGO
abrir
GitHub PoC4
D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins
CVE-2024-23897CRITICALbajo ataqueransomware08 dic 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC1
The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
CVE-2021-2301708 dic 2024
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir
GitHub PoC
Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server
CVE-2017-5638CRITICALbajo ataqueransomware08 dic 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
Technical Details and Exploit for CVE-2024-11392
CVE-2024-11392HIGH07 dic 2024
Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
41RIESGO
abrir
GitHub PoC
Calibre Remote Code Execution
CVE-2024-6782CRITICAL07 dic 2024
Calibre Remote Code Execution
85RIESGO
abrir
GitHub PoC3
POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method
CVE-2024-42327CRITICAL07 dic 2024
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC3
depers-rus/CVE-2024-42327
CVE-2024-42327CRITICAL06 dic 2024
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC
lu4m575/CVE-2024-35286_scan.nse
CVE-2024-35286CRITICAL06 dic 2024
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond
75RIESGO
abrir
GitHub PoC4
CVE-2024-10914 D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL06 dic 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC
fredagsguf/Windows-CVE-2024-38063
CVE-2024-38063CRITICAL06 dic 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
PoC for Watchguard CVE-2022-26318 updated to Python3.12
CVE-2022-26318CRITICALbajo ataque05 dic 2024
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RIESGO
abrir
GitHub PoC19
watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713
CVE-2024-41713CRITICALbajo ataqueransomware05 dic 2024
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
GitHub PoC1
Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en Chamilo LMS en versiones <= 1.11.24 permite a atacantes no autenticados realizar ataques de Cross Site Scripting almacenados y obtener código remoto ejecución mediante la carga de web shell.
CVE-2023-4220HIGH05 dic 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
Veeam Service Provider Console (VSPC) remote code execution.
CVE-2024-42448CRITICAL05 dic 2024
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos
53RIESGO
abrir
GitHub PoC4
D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB
CVE-2024-21413CRITICALbajo ataque04 dic 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2024-10914 is a critical vulnerability affecting the D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L up to version 20241028. The function cgi_user_add in the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add is the culprit, allowing attackers to inject operating system commands remotely.
CVE-2024-10914CRITICAL04 dic 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC
A Proof-of-Concept (PoC) exploit for CVE-2018-16763 (Fuel CMS - Preauthenticated Remote Code Execution).
CVE-2018-1676304 dic 2024
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC12
This repository contains a Proof of Concept (PoC) exploit for CVE-2024-11680, a critical vulnerability in ProjectSend r1605 and older versions. The exploit targets an improper authentication flaw due Privilege Misconfiguration issues.
CVE-2024-11680CRITICALbajo ataque04 dic 2024
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
GitHub PoC
Modified version of laravel ignition RCE (CVE-2021-3129) exploit script for Hour of Hack Session-4
CVE-2021-3129CRITICALbajo ataqueransomware04 dic 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC4
based on [EQSTLab](https://github.com/EQSTLab)
CVE-2024-46538CRITICAL04 dic 2024
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v
70RIESGO
abrir
GitHub PoC
A utility for Magento 2 encryption key rotation and management. CVE-2024-34102(aka Cosmic Sting) victims can use it as an aftercare.
CVE-2024-34102CRITICALbajo ataque04 dic 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC1
This is a exploit for CVE-2024-50498
CVE-2024-50498CRITICAL04 dic 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir
GitHub PoC
specializzazione-cyber-security/demo-CVE-2021-29447-lezione
CVE-2021-29447HIGH03 dic 2024
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
anteriorpágina 187 / 454siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.