Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.440exploits catalogados
34.431CVEs con explotación pública
24.695probados en laboratorio
13.624 exploits
GitHub PoC12
GiveWP PHP Object Injection exploit
CVE-2024-8353CRITICAL30 sep 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RIESGO
abrir
GitHub PoC10
POC - Jenkins File Read Vulnerability - CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware30 sep 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC8
p33d/CVE-2024-43917
CVE-2024-43917CRITICAL29 sep 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RIESGO
abrir
GitHub PoC10
CVE-2021-3129 (Laravel Ignition RCE Exploit)
CVE-2021-3129CRITICALbajo ataqueransomware29 sep 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC6
PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing server responses
CVE-2024-24919HIGHbajo ataqueransomware29 sep 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions
CVE-2024-36401CRITICALbajo ataque28 sep 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC42
p33d/CVE-2024-45519
CVE-2024-45519CRITICALbajo ataque28 sep 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir
GitHub PoC1
ADManager Plus Build < 7210 Elevation of Privilege Vulnerability
CVE-2024-24409HIGH28 sep 2024
Privilege Escalation
41RIESGO
abrir
GitHub PoC
Reproduction of SQL Injection Vulnerabilities in OpenHIS
CVE-2024-46532CRITICAL27 sep 2024
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the
48RIESGO
abrir
GitHub PoC
This is a demo for CVE-2024-32002 POC
CVE-2024-32002CRITICAL27 sep 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
This is a demo for CVE-2024-32002 POC
CVE-2024-32002CRITICAL27 sep 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
Proof of Concept for CVE-2024-32002
CVE-2024-32002CRITICAL27 sep 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a **malicious RAR archive** that triggers the execution of arbitrary code when the victim opens a benign-looking file within the archive (such as a PDF).
CVE-2023-38831HIGHbajo ataqueransomware27 sep 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
d
CVE-2023-38831HIGHbajo ataqueransomware26 sep 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
UMASANKAR-MG/Path-Traversal-CVE-2024-4956
CVE-2024-4956HIGH26 sep 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC
p33d/CVE-2024-8275
CVE-2024-8275CRITICAL26 sep 2024
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
60RIESGO
abrir
GitHub PoC3
A vulnerability scanner that searches for the CVE-2024-9166 vulnerability on websites, more info about this vulnerability here: https://www.tenable.com/cve/CVE-2024-9166
CVE-2024-9166CRITICAL26 sep 2024
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
63RIESGO
abrir
GitHub PoC8
Pgadmin4 Sensitive Information Exposure
CVE-2024-9014CRITICAL26 sep 2024
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RIESGO
abrir
GitHub PoC5
PrusaSlicer Arbitrary Code Execution using .3mf
CVE-2023-47268MEDIUM26 sep 2024
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RIESGO
abrir
GitHub PoC5
A proof of concept of traefik CVE to understand the impact
CVE-2024-45410CRITICAL26 sep 2024
HTTP client can remove the X-Forwarded headers in Traefik
48RIESGO
abrir
GitHub PoC
CVE-2024-46627 - Incorrect access control in BECN DATAGERRY v2.2 allows attackers to > execute arbitrary commands via crafted web requests.
CVE-2024-46627CRITICAL25 sep 2024
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
63RIESGO
abrir
GitHub PoC
CVE-2019-15107 webmin 취약점에 대해서 직접 서버를 구축하고 공격 결과를 남긴 정보입니다.
CVE-2019-15107CRITICALbajo ataqueransomware25 sep 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC7
Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVE-2024-28987CRITICALbajo ataque24 sep 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
GitHub PoC146
CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability
CVE-2024-38200MEDIUM24 sep 2024
Microsoft Office Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC3
WBW Product Table Pro <= 1.9.4 - Unauthenticated Arbitrary SQL Execution to RCE
CVE-2024-43918CRITICAL24 sep 2024
WordPress WBW Product Table PRO plugin <= 1.9.4 - Unauthenticated Arbitrary SQL Query Execution vulnerability
48RIESGO
abrir
GitHub PoC4
Proof-of-Concept for CVE-2024-47066
CVE-2024-47066CRITICAL24 sep 2024
Lobe Chat has insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
53RIESGO
abrir
GitHub PoC9
CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT]
CVE-2024-7593CRITICALbajo ataque24 sep 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RIESGO
abrir
GitHub PoC2
vidura2/CVE-2024-46377
CVE-2024-46377CRITICAL23 sep 2024
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function
48RIESGO
abrir
GitHub PoC5
TheCyberguy-17/RCE_CVE-2024-7954
CVE-2024-7954CRITICAL23 sep 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
GitHub PoC2
vidura2/CVE-2024-46451
CVE-2024-46451CRITICAL22 sep 2024
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the de
48RIESGO
abrir
anteriorpágina 197 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.