Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
13.618 exploits
GitHub PoC
rahisec/CVE-2024-4040
CVE-2024-4040CRITICALbajo ataque23 oct 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC1
bueno-armando/CVE-2023-4220-RCE
CVE-2023-4220HIGH23 oct 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC51
PfSense Stored XSS lead to Arbitrary Code Execution exploit
CVE-2024-46538CRITICAL23 oct 2024
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v
70RIESGO
abrir
GitHub PoC2
CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH.
CVE-2024-6387HIGH22 oct 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
grecosamuel/CVE-2024-32002
CVE-2024-32002CRITICAL22 oct 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC5
Arbitrary File Read and DoS in vendure-ecommerce exploit
CVE-2024-48914CRITICAL21 oct 2024
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
75RIESGO
abrir
GitHub PoC11
p33d/CVE-2024-23113
CVE-2024-23113CRITICALbajo ataque21 oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir
GitHub PoC
punitdarji/Grafana-CVE-2024-9264
CVE-2024-9264CRITICAL21 oct 2024
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC39
Grafana RCE exploit (CVE-2024-9264)
CVE-2024-9264CRITICAL21 oct 2024
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC7
File Read Proof of Concept for CVE-2024-9264
CVE-2024-9264CRITICAL20 oct 2024
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC5
Proof-of-Concept for LFI/Path Traversal vulnerability in Aiohttp =< 3.9.1
CVE-2024-23334MEDIUM20 oct 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC1
Affected versions of this package are vulnerable to Race Condition. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely.
CVE-2021-32708CRITICAL19 oct 2024
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
48RIESGO
abrir
GitHub PoC132
Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)
CVE-2024-9264CRITICAL19 oct 2024
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC11
Pre-Authentication Heap Overflow in Xlight SFTP server <= 3.9.4.2
CVE-2024-46483CRITICAL18 oct 2024
Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which c
48RIESGO
abrir
GitHub PoC2
Security Bulletin for CVE-2024-35133 - With PoC
CVE-2024-35133MEDIUM18 oct 2024
IBM Security Verify Access HTTP open redirect
33RIESGO
abrir
GitHub PoC
Vulnerability Overview CVE-2023-38408 affects OpenSSH versions < 9.3p2 and stems from improper validation of data when SSH agent forwarding is enabled. When users connect to a remote server with ssh -A, they allow the agent on their local machine to be used for authentication to further systems
CVE-2023-38408CRITICAL17 oct 2024
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC11
tdonaworth/Firefox-CVE-2024-9680
CVE-2024-9680CRITICALbajo ataqueransomware17 oct 2024
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli
83RIESGO
abrir
GitHub PoC2
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
CVE-2024-9234CRITICAL17 oct 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC
cuanh2333/CVE-2023-46604
CVE-2023-46604CRITICALbajo ataqueransomware16 oct 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC43
CVE-2024-40711-exp
CVE-2024-40711CRITICALbajo ataqueransomware16 oct 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RIESGO
abrir
GitHub PoC
Exploit and check CVE-2013-5211
CVE-2013-521116 oct 2024
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
GitHub PoC2
ADSelfService Plus RCE漏洞 检测工具 (二开)
CVE-2021-40539CRITICALbajo ataqueransomware16 oct 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RIESGO
abrir
GitHub PoC
check and exploit for NTP vuln CVE-2013-5211
CVE-2013-521116 oct 2024
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
GitHub PoC
idkwastaken/CVE-2023-38831
CVE-2023-38831HIGHbajo ataqueransomware15 oct 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC2
Guide and theoretical code for CVE-2023-35674
CVE-2023-35674HIGHbajo ataque15 oct 2024
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RIESGO
abrir
GitHub PoC5
ssst0n3/poc-cve-2024-0132
CVE-2024-0132CRITICAL15 oct 2024
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RIESGO
abrir
GitHub PoC
idkwastaken/CVE-2023-32560
CVE-2023-32560HIGH15 oct 2024
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RIESGO
abrir
GitHub PoC3
Vulnerability CVE-2024-38063
CVE-2024-38063CRITICAL15 oct 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
shanglyu/CVE-2024-1698
CVE-2024-1698CRITICAL14 oct 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC
idkwastaken/CVE-2024-38063
CVE-2024-38063CRITICAL14 oct 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
anteriorpágina 194 / 454siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.