Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.505exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
13.648 exploits
GitHub PoC
CVE-2017-8917 SQL injection Vulnerability in Joomla! 3.7.0 exploit
CVE-2017-891705 jun 2024
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC
Harydhk7/CVE-2024-4358
CVE-2024-4358CRITICALbajo ataque04 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC
junnythemarksman/CVE-2023-30547
CVE-2023-30547CRITICAL04 jun 2024
Sandbox Escape in vm2
70RIESGO
abrir
GitHub PoC1
0xans/CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware04 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
muhammad1596/CVE-2022-0847-dirty-pipe-checker
CVE-2022-0847HIGHbajo ataque04 jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
Tim-Hoekstra/CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware04 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC2
Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16
CVE-2024-21111HIGH04 jun 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RIESGO
abrir
GitHub PoC5
An Vulnerability detection and Exploitation tool for CVE-2024-4358
CVE-2024-4358CRITICALbajo ataque04 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC19
Apache HugeGraph Server Unauthenticated RCE - CVE-2024-27348 Proof of concept Exploit
CVE-2024-27348CRITICALbajo ataque03 jun 2024
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
GitHub PoC79
Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)
CVE-2024-4358CRITICALbajo ataque03 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC27
Apache OFBIZ Path traversal leading to RCE POC[CVE-2024-32113 & CVE-2024-36104]
CVE-2024-32113CRITICALbajo ataque03 jun 2024
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
GitHub PoC3
Sonatype Nexus Repository Manager 3 (LFI)
CVE-2024-4956HIGH03 jun 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC2
kevcooper/CVE-2024-1086-checker
CVE-2024-1086HIGHbajo ataqueransomware03 jun 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC1
CVE-2023-51518: Preauthenticated Java Deserialization via JMX in Apache James
CVE-2023-51518CRITICAL03 jun 2024
Apache James server: Privilege escalation via JMX pre-authentication deserialisation
48RIESGO
abrir
GitHub PoC4
Nmap script to check vulnerability CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware03 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
Exploit created by nu11secur1ty (https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2022-37706)
CVE-2022-37706HIGH03 jun 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC1
birdlex/cve-2024-24919-checker
CVE-2024-24919HIGHbajo ataqueransomware03 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
New exploit for Apache APISIX v2.12.1 - Remote code execution (RCE)
CVE-2022-24112CRITICALbajo ataque03 jun 2024
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC11
0nin0hanz0/CVE-2024-24919-PoC
CVE-2024-24919HIGHbajo ataqueransomware03 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC3
CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.
CVE-2024-24919HIGHbajo ataqueransomware03 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
J4F9S5D2Q7/CVE-2024-24919-CHECKPOINT
CVE-2024-24919HIGHbajo ataqueransomware02 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC3
CVE-2024-24919 Sniper - A powerful tool for scanning Check Point Security Gateway CVE-2024-24919 vulnerability. Supports single & bulk scanning, multithreading, and generates detailed CSV reports. Ideal for penetration testers and security researchers.
CVE-2024-24919HIGHbajo ataqueransomware02 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
a Proof of Concept of CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware02 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
mr-kasim-mehar/CVE-2024-24919-Exploit
CVE-2024-24919HIGHbajo ataqueransomware02 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
CVE-2021-41773.py
CVE-2021-41773HIGHbajo ataqueransomware02 jun 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
adyanamul/Remote-Code-Execution-RCE-Exploit-BlueKeep-CVE-2019-0708-PoC
CVE-2019-0708CRITICALbajo ataqueransomware02 jun 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
phpMyAdmin <4.9.0 - Cross-Site Request Forgery
CVE-2019-1261602 jun 2024
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF
28RIESGO
abrir
GitHub PoC
Mass scanner for CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware01 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
Exploit for CVE-2019-7609 in python
CVE-2019-7609CRITICALbajo ataque01 jun 2024
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC2
Check Point Security Gateway (LFI)
CVE-2024-24919HIGHbajo ataqueransomware01 jun 2024
Information disclosure
100RIESGO
abrir
anteriorpágina 220 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.