Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
13.618 exploits
GitHub PoC1
CVE-2024-54761 PoC
CVE-2024-54761MEDIUM15 nov 2024
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RIESGO
abrir
GitHub PoC2
Bash script to automate Local File Inclusion (LFI) attacks on aiohttp server version 3.9.1.
CVE-2024-23334MEDIUM14 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC
CiscoRV320Dump CVE-2019-1653 - Automatition.
CVE-2019-1653HIGHbajo ataque14 nov 2024
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
GitHub PoC
Fortigate SSL VPN buffer overflow exploit
CVE-2023-27997CRITICALbajo ataqueransomware14 nov 2024
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC1
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions leads to (RCE)
CVE-2024-52302HIGH14 nov 2024
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
41RIESGO
abrir
GitHub PoC4
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass
CVE-2024-10924CRITICAL14 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC
This script is specifically designed to solve the challenge on PentesterLab for the CVE-2013-0156 exploit
CVE-2013-015613 nov 2024
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir
GitHub PoC
Ivanti Cloud Services Appliance - Path Traversal
CVE-2024-8963CRITICALbajo ataque13 nov 2024
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RIESGO
abrir
GitHub PoC
CVE-2024-10914_Manual testing with burpsuite
CVE-2024-10914CRITICAL13 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC
https://nvd.nist.gov/vuln/detail/CVE-2023-4220
CVE-2023-4220HIGH13 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC2
working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln
CVE-2021-21425CRITICAL13 nov 2024
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
GitHub PoC1
Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability
CVE-2024-21534CRITICAL13 nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RIESGO
abrir
GitHub PoC
fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command
CVE-2021-3156HIGHbajo ataque13 nov 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
Attempt at making the CVE-2024-3400 initial exploit (for educational purposes)
CVE-2024-3400CRITICALbajo ataqueransomware12 nov 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC
harshtech123/cve-2020-24881
CVE-2020-2488112 nov 2024
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RIESGO
abrir
GitHub PoC1
Python POC for CVE-2024-32640 Mura CMS SQLi
CVE-2024-32640CRITICAL12 nov 2024
MasaCMS SQL Injection vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2022-21661 docker and poc
CVE-2022-21661HIGH12 nov 2024
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC1
This repository contains an exploit for CVE-2019-16278 in Nostromo Web Server 1.9.6, allowing remote code execution via a directory traversal vulnerability. The script uses pwntools to establish a reverse shell. For educational and authorized testing use only.
CVE-2019-16278CRITICALbajo ataque12 nov 2024
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC
CVE: 2015-1328 On python test
CVE-2015-132812 nov 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
GitHub PoC
uthrasri/CVE-2018-14881_no_patch
CVE-2018-14881CRITICAL11 nov 2024
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTA
48RIESGO
abrir
GitHub PoC1
oxapavan/CVE-2023-4220-HTB-PermX
CVE-2023-4220HIGH10 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC48
POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS
CVE-2024-10914CRITICAL10 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC
CVE-2024-47062 PoC
CVE-2024-47062CRITICAL10 nov 2024
Multiple SQL Injections and ORM Leak in navidrome
63RIESGO
abrir
GitHub PoC
In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10
CVE-2021-44228CRITICALbajo ataqueransomware10 nov 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
To test elasticsearch vulnerabillity on newer version of debian
CVE-2015-1427CRITICALbajo ataque10 nov 2024
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
GitHub PoC
Automatic Translation <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2024-50493CRITICAL10 nov 2024
WordPress Automatic Translation plugin <= 1.0.4 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC1
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
CVE-2024-10586CRITICAL10 nov 2024
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RIESGO
abrir
GitHub PoC
sea-middle/cve-2023-25813
CVE-2023-25813CRITICAL09 nov 2024
SQL Injection via replacements in sequelize
48RIESGO
abrir
GitHub PoC
WP Dropbox Dropins <= 1.0 - Unauthenticated Arbitrary File Upload
CVE-2024-49607CRITICAL09 nov 2024
WordPress WP Dropbox Dropins plugin <= 1.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
Ajar in5 Embed <= 3.1.3 - Unauthenticated Arbitrary File Upload
CVE-2024-50473CRITICAL09 nov 2024
WordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerability
48RIESGO
abrir
anteriorpágina 191 / 454siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.