Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC
Case Study: SSHtranger Things (CVE-2019-6111, CVE-2019-6110) in Cisco SD-WAN
CVE-2019-6111MEDIUM01 jul 2024
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RIESGO
abrir
GitHub PoC
Exploit script showcasing a mixture of CVE-2019-18818 and CVE-2019-19609 for unauthenticated remote code execution in Strapi CMS.
CVE-2019-1881801 jul 2024
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
GitHub PoC9
CosmicSting: critical unauthenticated XXE vulnerability in Adobe Commerce and Magento (CVE-2024-34102)
CVE-2024-34102CRITICALbajo ataque01 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
cmsec423/Magento-XXE-CVE-2024-34102
CVE-2024-34102CRITICALbajo ataque01 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC493
a signal handler race condition in OpenSSH's server (sshd)
CVE-2024-6387HIGH01 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
a signal handler race condition in OpenSSH's server (sshd)
CVE-2024-6387HIGH01 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC129
MIRROR of the original 32-bit PoC for CVE-2024-6387 "regreSSHion" by 7etsuo/cve-2024-6387-poc
CVE-2024-6387HIGH01 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC24
PoC RCE in OpenSSH
CVE-2024-6387HIGH01 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC
SSHd cve-2024-6387-poc
CVE-2024-6387HIGH01 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
passwa11/cve-2024-6387-poc
CVE-2024-6387HIGH01 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC
jack0we/CVE-2024-6387
CVE-2024-6387HIGH01 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC526
CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH
CVE-2024-6387HIGH01 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC380
32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc
CVE-2024-6387HIGH01 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC34
CVE-2024-28955 Exploitation PoC
CVE-2024-28995HIGHbajo ataque01 jul 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir
GitHub PoC
Magento XXE
CVE-2024-34102CRITICALbajo ataque01 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC2
CVE-2024-34102 (Magento XXE)
CVE-2024-34102CRITICALbajo ataque30 jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC4
This is a proof of concept for the Zyxel vulnerabilities I found. Read the blog :)
CVE-2024-29972CRITICAL30 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RIESGO
abrir
GitHub PoC1
PavilionQ/CVE-2023-33246-mitigation
CVE-2023-33246CRITICALbajo ataque29 jun 2024
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC
CVE-2023-6553 exploit script
CVE-2023-6553CRITICAL29 jun 2024
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir
GitHub PoC
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.
CVE-2024-22853CRITICAL29 jun 2024
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote a
48RIESGO
abrir
GitHub PoC
phpMyAdmin 2.6.4-pl1 - Directory Traversal
CVE-2005-329929 jun 2024
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to in
28RIESGO
abrir
GitHub PoC3
POC for CVE-2024-34102 : Unauthenticated Magento XXE and bypassing WAF , You will get http connection on ur webhook
CVE-2024-34102CRITICALbajo ataque28 jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
A PoC demonstration , critical XML entity injection vulnerability in Magento
CVE-2024-34102CRITICALbajo ataque28 jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
scirusvulgaris/CVE-2017-12617
CVE-2017-12617HIGHbajo ataque28 jun 2024
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC1
CocoaPods RCE Vulnerability CVE-2024-38366
CVE-2024-38366CRITICAL28 jun 2024
CoacoaPods trunk RCE in email verification system rfc-822
53RIESGO
abrir
GitHub PoC48
CosmicSting (CVE-2024-34102)
CVE-2024-34102CRITICALbajo ataque28 jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
CVE-2024-4040 PoC
CVE-2024-4040CRITICALbajo ataque28 jun 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC
CVE-2024-21413 PoC
CVE-2024-21413CRITICALbajo ataque28 jun 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware28 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
Modified RCE with a remote shell and logging
CVE-2023-34362CRITICALbajo ataqueransomware28 jun 2024
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
anteriorpágina 213 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.