Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC1
CVE-2024-39700 Proof of Concept
CVE-2024-39700CRITICAL29 jul 2024
Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action
48RIESGO
abrir
GitHub PoC
A Reverse shell generator for gitlab-shell vulnerability cve 2024-32002
CVE-2024-32002CRITICAL28 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC2
vvts-alpha/CVE-2010-0219
CVE-2010-021928 jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
GitHub PoC
CVE-2024-23897 exploit script
CVE-2024-23897CRITICALbajo ataqueransomware28 jul 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC5
CVE-2024-4879 & CVE-2024-5217 ServiceNow RCE Scanning Using Nuclei & Shodan Dork to find it.
CVE-2024-4879CRITICALbajo ataque28 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
GitHub PoC
This repository contains scripts and resources for exploiting the Follina CVE and CVE-2021-40444 vulnerabilities in Microsoft Office. The scripts generate malicious document files that can execute arbitrary code on the target system.
CVE-2021-40444HIGHbajo ataqueransomware28 jul 2024
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
veritas-rt/CVE-2010-0219
CVE-2010-021928 jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
GitHub PoC2
Questa repository contiene una replica (tentativo di replica) scritto in Python per CVE-2024-30088.
CVE-2024-30088HIGHbajo ataqueransomware27 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC
blackninja23/CVE-2024-32002
CVE-2024-32002CRITICAL27 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
CERTologists/HTTP-Request-for-PHP-object-injection-attack-on-CVE-2023-41892
CVE-2023-41892CRITICAL27 jul 2024
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC1
AndreaF17/PoC-CVE-2024-44349
CVE-2024-44349CRITICAL26 jul 2024
A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute ar
63RIESGO
abrir
GitHub PoC
PauloParoPP/CVE-2024-41110-SCAN
CVE-2024-41110CRITICAL26 jul 2024
Moby authz zero length regression
53RIESGO
abrir
GitHub PoC
CVE-2021-44228 vulnerability study
CVE-2021-44228CRITICALbajo ataqueransomware26 jul 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Jutrm/cve-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware26 jul 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.
CVE-2023-7028CRITICALbajo ataque25 jul 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
GitHub PoC2
prelearn-code/CVE-2024-6387
CVE-2024-6387HIGH25 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC6
vvpoglazov/cve-2024-41110-checker
CVE-2024-41110CRITICAL25 jul 2024
Moby authz zero length regression
53RIESGO
abrir
GitHub PoC
ps4 cve-2008-3531
CVE-2008-353124 jul 2024
Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled,
23RIESGO
abrir
GitHub PoC
a-roshbaik/CVE-2024-4577-PHP-RCE
CVE-2024-4577CRITICALbajo ataqueransomware24 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
a-roshbaik/CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware24 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
Tool for checking Nginx CVE-2013-2028
CVE-2013-202823 jul 2024
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir
GitHub PoC
CERTologists/EXPLOITING-CVE-2024-27956
CVE-2024-27956CRITICAL23 jul 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC23
Updated Exploit - pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL23 jul 2024
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
GitHub PoC2
Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode exploitation technique.
CVE-2023-38831HIGHbajo ataqueransomware23 jul 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
a test repository for CVE-2018-17456's PoC
CVE-2018-1745622 jul 2024
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir
GitHub PoC
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised users.
CVE-2021-43798HIGHbajo ataque22 jul 2024
Grafana path traversal
100RIESGO
abrir
GitHub PoC
Hello everyone, I am sharing a modified script from CVE-2024-24919 which can extract paths categorized as critical.
CVE-2024-24919HIGHbajo ataqueransomware22 jul 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
CVE 2023-22515
CVE-2023-22515CRITICALbajo ataqueransomware21 jul 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC
TSY244/CVE-2024-32002-git-rce
CVE-2024-32002CRITICAL20 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
TSY244/CVE-2024-32002-git-rce-father-poc
CVE-2024-32002CRITICAL20 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
anteriorpágina 207 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.