Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC
Educational exploit for CVE-2022-30190
CVE-2022-30190HIGHbajo ataqueransomware20 jul 2024
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
TSY244/CVE-2024-32002-git-rce
CVE-2024-32002CRITICAL20 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
CVE-2022-37706-Enlightenment v0.25.3 - Privilege escalation
CVE-2022-37706HIGH19 jul 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC
Wytchwulf/CVE-2015-1397-Magento-Shoplift
CVE-2015-139719 jul 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir
GitHub PoC4
Vulnerability checking tool via Nmap Scripting Engine
CVE-2023-22515CRITICALbajo ataqueransomware18 jul 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC2
Proof Of Concept for CVE-2024-1874
CVE-2024-1874CRITICAL18 jul 2024
Command injection via array-ish $command parameter of proc_open()
60RIESGO
abrir
GitHub PoC1
Script para eliminar vulnerabilidad de openssh de ubuntu 22.04 LTS
CVE-2023-38408CRITICAL17 jul 2024
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC3
Exploit for CVE-2024-31989.
CVE-2024-31989CRITICAL17 jul 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache
48RIESGO
abrir
GitHub PoC43
geoserver CVE-2024-36401漏洞利用工具
CVE-2024-36401CRITICALbajo ataque17 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC1
Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases
CVE-2024-4879CRITICALbajo ataque16 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
GitHub PoC
Laravel Debug Mode and Payload
CVE-2021-3129CRITICALbajo ataqueransomware16 jul 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
On October 4, 2021, Apache HTTP Server Project released Security advisory on a Path traversal and File disclosure vulnerability in Apache HTTP Server 2.4.49 and 2.4.50 tracked as CVE-2021-41773 and CVE-2021-42013. In the advisory, Apache also highlighted “the issue is known to be exploited in the wild” and later it was identified that the vulnerabi
CVE-2021-42013CRITICALbajo ataqueransomware16 jul 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
Automated PHP remote code execution scanner for CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware16 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
khanhtranngoccva/cve-2023-38831-poc
CVE-2023-38831HIGHbajo ataqueransomware16 jul 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC525
Kernel exploit for Xbox SystemOS using CVE-2024-30088
CVE-2024-30088HIGHbajo ataqueransomware15 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC2
OpenSSH RCE Massive Vulnerable Scanner
CVE-2024-6387HIGH15 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC
LMS Chamilo 1.11.24 CVE-2023-4220 Exploit
CVE-2023-4220HIGH15 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC1
Phantom-IN/CVE-2024-34102
CVE-2024-34102CRITICALbajo ataque14 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire
CVE-2024-6387HIGH14 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
Exploit para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).
CVE-2014-6271CRITICALbajo ataque14 jul 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
Prueba de concepto para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).
CVE-2014-6271CRITICALbajo ataque14 jul 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
CVE-2024-39250 TimeTrax SQLi
CVE-2024-39250CRITICAL13 jul 2024
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t
63RIESGO
abrir
GitHub PoC5
Exploitation CVE-2024-34102
CVE-2024-34102CRITICALbajo ataque13 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC76
CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit
CVE-2024-41570CRITICAL13 jul 2024
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RIESGO
abrir
GitHub PoC10
Bulk scanning tool for ServiceNow CVE-2024-4879 vulnerability
CVE-2024-4879CRITICALbajo ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
GitHub PoC
jakabakos/CVE-2024-36401-GeoServer-RCE
CVE-2024-36401CRITICALbajo ataque12 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC26
CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow
CVE-2024-4879CRITICALbajo ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
GitHub PoC4
CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
CVE-2024-4879CRITICALbajo ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
GitHub PoC
BlackFrog-hub/cve-2015-1328
CVE-2015-132812 jul 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
GitHub PoC5
ATTACK PoC - PHP CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware11 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
anteriorpágina 208 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.