Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
13.654 exploits
GitHub PoC27
CVE-2023-34992: Fortinet FortiSIEM Command Injection Proof of Concept Exploit
CVE-2023-34992CRITICAL17 may 2024
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RIESGO
abrir
GitHub PoC
CVE-2019-9054 exploit added support for python3 + bug fixes
CVE-2019-905317 may 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and https://github.com/ly4k/CurveBall
CVE-2020-0601HIGHbajo ataque16 may 2024
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC13
Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados
CVE-2024-23897CRITICALbajo ataqueransomware16 may 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC1
Cacti CVE-2024-29895 POC
CVE-2024-29895CRITICAL16 may 2024
Cacti command injection in cmd_realtime.php
85RIESGO
abrir
GitHub PoC78
CVE-2024-32640 | Automated SQLi Exploitation PoC
CVE-2024-32640CRITICAL16 may 2024
MasaCMS SQL Injection vulnerability
85RIESGO
abrir
GitHub PoC
ticofookfook/CVE-2024-29895.py
CVE-2024-29895CRITICAL16 may 2024
Cacti command injection in cmd_realtime.php
85RIESGO
abrir
GitHub PoC
CVE-2016-10033 Wordpress 4.6 Exploit
CVE-2016-10033CRITICALbajo ataque16 may 2024
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC1
PoC for CVE-2018-14716
CVE-2018-1471615 may 2024
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques
35RIESGO
abrir
GitHub PoC1
PoC for CVE-2021-34646
CVE-2021-34646CRITICAL15 may 2024
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RIESGO
abrir
GitHub PoC23
CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds
CVE-2024-29895CRITICAL15 may 2024
Cacti command injection in cmd_realtime.php
85RIESGO
abrir
GitHub PoC
W3BW/CVE-2024-27956-RCE-File-Package
CVE-2024-27956CRITICAL15 may 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC4
High CVE-2024-4761 Exploit
CVE-2024-4761HIGHbajo ataque14 may 2024
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds
76RIESGO
abrir
GitHub PoC2
Checker for CVE-2021-3156 with static version check
CVE-2021-3156HIGHbajo ataque14 may 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
CVE-2024-34832
CVE-2024-34832CRITICAL14 may 2024
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a craf
48RIESGO
abrir
GitHub PoC15
aelmokhtar/CVE-2024-34716
CVE-2024-34716CRITICAL14 may 2024
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RIESGO
abrir
GitHub PoC5
jakabakos/CVE-2023-26360-adobe-coldfusion-rce-exploit
CVE-2023-26360HIGHbajo ataque14 may 2024
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
GitHub PoC2
POC for CVE-2024-4701
CVE-2024-4701CRITICAL13 may 2024
Path Traversal vulnerability via File Uploads in Genie
53RIESGO
abrir
GitHub PoC
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
CVE-2024-4040CRITICALbajo ataque13 may 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC1
Updated python3 exploit for CVE-2018-10583 (LibreOffice/Open Office - '.odt' Information Disclosure )
CVE-2018-1058313 may 2024
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RIESGO
abrir
GitHub PoC
andrelia-hacks/CVE-2024-3400
CVE-2024-3400CRITICALbajo ataqueransomware12 may 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC7
Kernel Exploit for CVE-2016-6187 (Local Privilege Escalation)
CVE-2016-618712 may 2024
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RIESGO
abrir
GitHub PoC
th3Hellion/CVE-2024-21413
CVE-2024-21413CRITICALbajo ataque11 may 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
Apache Superset - Authentication Bypass
CVE-2023-27524HIGHbajo ataque11 may 2024
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC1
Tool for finding CVE-2023-27524 (Apache Superset - Authentication Bypass)
CVE-2023-27524HIGHbajo ataque11 may 2024
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
GitHub PoC
rasan2001/CVE-2023-27350-Ongoing-Exploitation-of-PaperCut-Remote-Code-Execution-Vulnerability
CVE-2023-27350CRITICALbajo ataqueransomware10 may 2024
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC
rasan2001/Microsoft-Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware10 may 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
Shelly is a lightweight and efficient vulnerability scanner designed to identify and mitigate Shellshock (CVE-2014-6271 & CVE-2014-7169) vulnerabilities in Bash environments.
CVE-2014-6271CRITICALbajo ataque10 may 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
shaily29-eng/CyberSecurity_CVE-2021-45046
CVE-2021-45046CRITICALbajo ataqueransomware09 may 2024
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC1
xbz0n/CVE-2024-0566
CVE-2024-0566HIGH09 may 2024
Smart Manager < 8.28.0 - Admin+ SQL Injection
41RIESGO
abrir
anteriorpágina 226 / 456siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.