Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
13.618 exploits
GitHub PoC
0xDTC/Magento-eCommerce-RCE-CVE-2015-1397
CVE-2015-139727 nov 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir
GitHub PoC1
Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible
CVE-2014-6271CRITICALbajo ataque26 nov 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2021-36260CRITICALbajo ataque26 nov 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2017-7921CRITICALbajo ataque26 nov 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2022-28171HIGH26 nov 2024
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
53RIESGO
abrir
GitHub PoC1
Proof Of Concept for the CVE-2012-1831 (Kingview Touchview 6.53). This is a Industrial Control Systems Vulnerability
CVE-2012-183126 nov 2024
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted p
28RIESGO
abrir
GitHub PoC3
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation
CVE-2024-10542CRITICAL26 nov 2024
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
53RIESGO
abrir
GitHub PoC96
synacktiv/CVE-2024-43468
CVE-2024-43468CRITICALbajo ataque26 nov 2024
Microsoft Configuration Manager Remote Code Execution Vulnerability
90RIESGO
abrir
GitHub PoC
Working Dirty Pipe (CVE-2022-0847) exploit tool with root access and file overwrites.
CVE-2022-0847HIGHbajo ataque25 nov 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
Picsmize <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-52380CRITICAL25 nov 2024
WordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you cannot upgrade Magento or cannot apply the official patches, try this one.
CVE-2022-24086CRITICALbajo ataque25 nov 2024
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir
GitHub PoC
Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection
CVE-2024-52430CRITICAL25 nov 2024
WordPress Lis Video Gallery plugin <= 0.2.1 - PHP Object Injection vulnerability
48RIESGO
abrir
GitHub PoC
YassDEV221608/CVE-2024-6387
CVE-2024-6387HIGH24 nov 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC
francescobrina/hfs-cve-2014-6287-exploit
CVE-2014-6287CRITICALbajo ataque24 nov 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC
WolffCorentin/CVE-2019-1663-Binary-Analysis
CVE-2019-1663CRITICAL24 nov 2024
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir
GitHub PoC1
Xss injection, WonderCMS 3.2.0 -3.4.2
CVE-2023-41425MEDIUM24 nov 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
GitHub PoC1
Remote Command Execution into shell from a vulnerable exim service.
CVE-2019-10149CRITICALbajo ataque24 nov 2024
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC
0-Gram/CVE-2022-41040
CVE-2022-41040HIGHbajo ataqueransomware23 nov 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
BohemianHacks/CVE-2024-21534-poc
CVE-2024-21534CRITICAL23 nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RIESGO
abrir
GitHub PoC1
CVE-2024-32002 是 Git 中的一个严重漏洞,允许攻击者在用户执行 git clone 操作时远程执行任意代码(RCE)。
CVE-2024-32002CRITICAL23 nov 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
CVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。
CVE-2023-20198CRITICALbajo ataque23 nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC24
CVE-2024-35250 的 Beacon Object File (BOF) 实现。
CVE-2024-35250HIGHbajo ataque23 nov 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir
GitHub PoC
CVE-2024-0012是Palo Alto Networks PAN-OS软件中的一个身份验证绕过漏洞。该漏洞允许未经身份验证的攻击者通过网络访问管理Web界面,获取PAN-OS管理员权限,从而执行管理操作、篡改配置,或利用其他需要身份验证的特权提升漏洞(如CVE-2024-9474)
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC
My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection
CVE-2024-52433CRITICAL22 nov 2024
WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
63RIESGO
abrir
GitHub PoC
punitdarji/Paloalto-CVE-2024-0012
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC2
CVE-2024-0012批量检测脚本
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC
Broken Authentication in Wordpress plugin (Wawp Plugin < 3.0.18)
CVE-2024-52475CRITICAL22 nov 2024
WordPress Wawp plugin < 3.0.18 - Account Takeover vulnerability
48RIESGO
abrir
GitHub PoC2
This tool scans WordPress websites for vulnerabilities in the WP Time Capsule plugin related to CVE-2024-8856. It identifies plugin versions below 1.22.22 as vulnerable and logs results to vuln.txt. Simple and efficient, it helps security researchers and admins detect and address risks quickly.
CVE-2024-8856CRITICAL21 nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir
GitHub PoC1
This is POC of CVE-2024-29671
CVE-2024-29671CRITICAL21 nov 2024
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code vi
53RIESGO
abrir
GitHub PoC1
This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific version (`6.0.2.6`) and marks the site as vulnerable if found. The results are saved in a file (`vuln.txt`) for further analysis.
CVE-2024-10508CRITICAL21 nov 2024
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
48RIESGO
abrir
anteriorpágina 189 / 454siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.