Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.447exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC
A script to exploit CVE-2020-1472 (Zerologon)
CVE-2020-1472MEDIUMbajo ataqueransomware06 jun 2024
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
NanoWraith/CVE-2024-25600
CVE-2024-25600CRITICAL06 jun 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
DigitalNinja00/CVE-2018-1335
CVE-2018-133506 jun 2024
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
GitHub PoC
sql延时注入poc
CVE-2024-32640CRITICAL06 jun 2024
MasaCMS SQL Injection vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2021-1675/CVE-2021-34527 PrintNightmare & CVE-2020-0668
CVE-2021-1675HIGHbajo ataqueransomware05 jun 2024
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
This script will inform the user if the Confluence instance is vulnerable, but it will not proceed with the exploitation steps.
CVE-2023-22515CRITICALbajo ataqueransomware05 jun 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC1
Oracle WebLogic Server (LFI)
CVE-2022-21371HIGH05 jun 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RIESGO
abrir
GitHub PoC26
Sk1dr0wz/CVE-2024-4358_Mass_Exploit
CVE-2024-4358CRITICALbajo ataque05 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2017-8917 SQL injection Vulnerability in Joomla! 3.7.0 exploit
CVE-2017-891705 jun 2024
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC9
CVE-2024-4956 Python exploitation utility
CVE-2024-4956HIGH05 jun 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC1
0xans/CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware04 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC2
Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16
CVE-2024-21111HIGH04 jun 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RIESGO
abrir
GitHub PoC5
An Vulnerability detection and Exploitation tool for CVE-2024-4358
CVE-2024-4358CRITICALbajo ataque04 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC
Tim-Hoekstra/CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware04 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
Harydhk7/CVE-2024-4358
CVE-2024-4358CRITICALbajo ataque04 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC1
muhammad1596/CVE-2022-0847-dirty-pipe-checker
CVE-2022-0847HIGHbajo ataque04 jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
junnythemarksman/CVE-2023-30547
CVE-2023-30547CRITICAL04 jun 2024
Sandbox Escape in vm2
70RIESGO
abrir
GitHub PoC19
Apache HugeGraph Server Unauthenticated RCE - CVE-2024-27348 Proof of concept Exploit
CVE-2024-27348CRITICALbajo ataque03 jun 2024
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
GitHub PoC2
kevcooper/CVE-2024-1086-checker
CVE-2024-1086HIGHbajo ataqueransomware03 jun 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC27
Apache OFBIZ Path traversal leading to RCE POC[CVE-2024-32113 & CVE-2024-36104]
CVE-2024-32113CRITICALbajo ataque03 jun 2024
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
GitHub PoC4
Nmap script to check vulnerability CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware03 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC3
CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.
CVE-2024-24919HIGHbajo ataqueransomware03 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC11
0nin0hanz0/CVE-2024-24919-PoC
CVE-2024-24919HIGHbajo ataqueransomware03 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
birdlex/cve-2024-24919-checker
CVE-2024-24919HIGHbajo ataqueransomware03 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC3
Sonatype Nexus Repository Manager 3 (LFI)
CVE-2024-4956HIGH03 jun 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC1
CVE-2023-51518: Preauthenticated Java Deserialization via JMX in Apache James
CVE-2023-51518CRITICAL03 jun 2024
Apache James server: Privilege escalation via JMX pre-authentication deserialisation
48RIESGO
abrir
GitHub PoC1
New exploit for Apache APISIX v2.12.1 - Remote code execution (RCE)
CVE-2022-24112CRITICALbajo ataque03 jun 2024
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC
Exploit created by nu11secur1ty (https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2022-37706)
CVE-2022-37706HIGH03 jun 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC79
Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)
CVE-2024-4358CRITICALbajo ataque03 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC1
adyanamul/Remote-Code-Execution-RCE-Exploit-BlueKeep-CVE-2019-0708-PoC
CVE-2019-0708CRITICALbajo ataqueransomware02 jun 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
anteriorpágina 219 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.