Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
CVE-2023-4596CRITICAL06 ago 2024
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
CVE-2024-6387HIGH06 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC2
A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4
CVE-2011-252303 ago 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
Abdurahmon3236/CVE-2024-6366
CVE-2024-6366CRITICAL03 ago 2024
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RIESGO
abrir
GitHub PoC
Abdurahmon3236/CVE-2024-36539
CVE-2024-36539CRITICAL03 ago 2024
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t
48RIESGO
abrir
GitHub PoC
nastar-id/CVE-2024-32700
CVE-2024-32700CRITICAL03 ago 2024
WordPress Kognetiks Chatbot for WordPress plugin <= 2.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
adapting CVE-2024-32002 for running offline and locally
CVE-2024-32002CRITICAL02 ago 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
Proof of concept exploit for CVE-2021-21551
CVE-2021-21551HIGHbajo ataque02 ago 2024
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC2
Vulnerability Scanner for CVE-2024-37085 and Exploits ( For Educational Purpose only)
CVE-2024-37085MEDIUMbajo ataqueransomware02 ago 2024
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RIESGO
abrir
GitHub PoC
Abdurahmon3236/CVE-2024-40110
CVE-2024-40110CRITICAL02 ago 2024
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
CVE-2023-4220HIGH02 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
y1s4s/CVE-2024-36401-PoC
CVE-2024-36401CRITICALbajo ataque01 ago 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC1
apena-ba/CVE-2024-39304
CVE-2024-39304HIGH31 jul 2024
ChurchCRM SQL Injection Vulnerability
41RIESGO
abrir
GitHub PoC
Exploit script for CVE-2022-41544 in GetSimple CMS, with enhanced error handling and detailed usage instructions.
CVE-2022-41544HIGH31 jul 2024
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
41RIESGO
abrir
GitHub PoC
批量验证POC和EXP
CVE-2024-4577CRITICALbajo ataqueransomware31 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC1
bananoname/cve-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware31 jul 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
An exploit for CVE-2024-6387, targeting a signal handler race condition in OpenSSH's server
CVE-2024-6387HIGH31 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
12
CVE-2023-25813CRITICAL30 jul 2024
SQL Injection via replacements in sequelize
48RIESGO
abrir
GitHub PoC12
Proof of concept python script for regreSSHion exploit.
CVE-2024-6387HIGH30 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC86
GeoServer Remote Code Execution
CVE-2024-36401CRITICALbajo ataque30 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC
FlojBoj/CVE-2024-32002
CVE-2024-32002CRITICAL30 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
KaSooMi0228/CVE-2024-25600-Bricks-Builder-WordPress
CVE-2024-25600CRITICAL30 jul 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC3
PoC of CVE-2024-32002 - Remote Code Execution while cloning special-crafted local repositories
CVE-2024-32002CRITICAL30 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
Just small script to exploit CVE-2024-32002
CVE-2024-32002CRITICAL30 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC2
PoC for CVE-2024-34144
CVE-2024-34144CRITICAL29 jul 2024
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_
60RIESGO
abrir
GitHub PoC
projectforsix/CVE-2021-45428-Defacer
CVE-2021-4542829 jul 2024
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RIESGO
abrir
GitHub PoC80
Windows AppLocker Driver (appid.sys) LPE
CVE-2024-21338HIGHbajo ataqueransomware29 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC
GIT RCE CVE-2024-32002
CVE-2024-32002CRITICAL29 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
CVE-2024-39700 Proof of Concept
CVE-2024-39700CRITICAL29 jul 2024
Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action
48RIESGO
abrir
GitHub PoC
Blind SQL Injection to RCE in a PHP open source application
CVE-2024-40498CRITICAL29 jul 2024
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbit
48RIESGO
abrir
anteriorpágina 206 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.