Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.444exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC2
vidura2/CVE-2024-46377
CVE-2024-46377CRITICAL23 sep 2024
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function
48RIESGO
abrir
GitHub PoC5
TheCyberguy-17/RCE_CVE-2024-7954
CVE-2024-7954CRITICAL23 sep 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
GitHub PoC3
vidura2/CVE-2024-46986
CVE-2024-46986CRITICAL22 sep 2024
Arbitrary file write leading to RCE in Camaleon CMS
75RIESGO
abrir
GitHub PoC2
vidura2/CVE-2024-46451
CVE-2024-46451CRITICAL22 sep 2024
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the de
48RIESGO
abrir
GitHub PoC
Kode Eksploitasi CVE-2024-38063
CVE-2024-38063CRITICAL21 sep 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
CVE-2024-3273 - D-Link Remote Code Execution (RCE)
CVE-2024-3273HIGHbajo ataque21 sep 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir
GitHub PoC
WonderCMS RCE CVE-2023-41425
CVE-2023-41425MEDIUM21 sep 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
GitHub PoC3
Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053
CVE-2019-905321 sep 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
MAHajian/CVE-2019-9978
CVE-2019-9978MEDIUMbajo ataque20 sep 2024
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC
btar1gan/exploit_CVE-2022-35914
CVE-2022-35914CRITICALbajo ataque20 sep 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
GitHub PoC1
teamcity-exploit-cve-2023-42793
CVE-2023-42793CRITICALbajo ataqueransomware20 sep 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC
yashfren/CVE-2014-0160-HeartBleed
CVE-2014-0160HIGHbajo ataque20 sep 2024
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC6
POC_CVE-2024-46256
CVE-2024-46256CRITICAL19 sep 2024
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RIESGO
abrir
GitHub PoC1
Modification of: PoC of CVE-2019-14322: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-1432219 sep 2024
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RIESGO
abrir
GitHub PoC2
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
CVE-2024-8522CRITICAL19 sep 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RIESGO
abrir
GitHub PoC
Webrun <= 3.6.0.42 SQLi
CVE-2021-4365019 sep 2024
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
23RIESGO
abrir
GitHub PoC
CVE-2023-47253 | Qualitor <= 8.20 RCE
CVE-2023-47253CRITICAL19 sep 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RIESGO
abrir
GitHub PoC
MLFlow Path Traversal
CVE-2023-1177CRITICAL19 sep 2024
Path Traversal: '\..\filename' in mlflow/mlflow
75RIESGO
abrir
GitHub PoC
CVE-2023-47253 | Qualitor <= 8.20 RCE
CVE-2023-47253CRITICAL19 sep 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RIESGO
abrir
GitHub PoC
poc of cve-2024-8752(WebIQ 2.15.9)
CVE-2024-8752CRITICAL19 sep 2024
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
68RIESGO
abrir
GitHub PoC
safeer-accuknox/CrushFTP-cve-2024-4040-poc
CVE-2024-4040CRITICALbajo ataque18 sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC4
CVE-2022-23131 Zabbix Server SAML authentication exploit
CVE-2022-23131CRITICALbajo ataque18 sep 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC2
0xAgun/CVE-2024-2876
CVE-2024-2876CRITICAL17 sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC2
The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads
CVE-2024-43160CRITICAL17 sep 2024
WordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability
63RIESGO
abrir
GitHub PoC3
Client Implementation for the WatchGuard SSO Agent Protocol used for Security Research (CVE-2024-6592, CVE-2024-6593, CVE-2024-6594)
CVE-2024-6592CRITICAL17 sep 2024
WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
48RIESGO
abrir
GitHub PoC1
PoC code for vulnerability in webmod v0.48. Originally written in 2007, assigned CVE-2007-1260.
CVE-2007-126016 sep 2024
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RIESGO
abrir
GitHub PoC3
CVE-2024-44000-LiteSpeed-Cache
CVE-2024-44000CRITICAL16 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
GitHub PoC16
CVE-2024-8190: Ivanti Cloud Service Appliance Command Injection
CVE-2024-8190HIGHbajo ataque16 sep 2024
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RIESGO
abrir
GitHub PoC
Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!
CVE-2021-3493HIGHbajo ataque16 sep 2024
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC4
Server-Side Template Injection Exploit
CVE-2024-32651CRITICAL16 sep 2024
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RIESGO
abrir
anteriorpágina 198 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.