Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
13.654 exploits
GitHub PoC1
xbz0n/CVE-2024-0566
CVE-2024-0566HIGH09 may 2024
Smart Manager < 8.28.0 - Admin+ SQL Injection
41RIESGO
abrir
GitHub PoC16
GUI Exploit Tool for CVE-2020-0688(Microsoft Exchange default MachineKeySection deserialize vulnerability)
CVE-2020-0688HIGHbajo ataqueransomware09 may 2024
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC
shaily29-eng/CyberSecurity_CVE-2021-45046
CVE-2021-45046CRITICALbajo ataqueransomware09 may 2024
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC
jrbH4CK/CVE-2022-22963
CVE-2022-22963CRITICALbajo ataque08 may 2024
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC
CVE-2024-27956
CVE-2024-27956CRITICAL07 may 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC18
PoC for Exploiting CVE-2024-31848/49/50/51 - File Path Traversal
CVE-2024-31848CRITICAL07 may 2024
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedde
63RIESGO
abrir
GitHub PoC4
Critical use-after-free vulnerability discovered in Tinyproxy
CVE-2023-49606CRITICAL07 may 2024
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A
60RIESGO
abrir
GitHub PoC
[CVE-2024-23897] Jenkins CI Authenticated Arbitrary File Read Through the CLI Leads to Remote Code Execution (RCE)
CVE-2024-23897CRITICALbajo ataqueransomware07 may 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC7
LINKSYS AC1900 EA7500v3 IGD UPnP Stack Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-46012CRITICAL06 may 2024
Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP
48RIESGO
abrir
GitHub PoC1
An issue in HSC Cybersecurity HSC Mailinspector version 5.2.17-3 has been identified, allowing a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.
CVE-2024-32370CRITICAL06 may 2024
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive info
48RIESGO
abrir
GitHub PoC
GalloLuigi/Analisi-CVE-2017-5715
CVE-2017-5715MEDIUM06 may 2024
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
GitHub PoC
Turvanõrkuse CVE 2024 3273 analüüs: D-Link seadmete käsusüst
CVE-2024-3273HIGHbajo ataque05 may 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir
GitHub PoC2
PoC for the Untrusted Pointer Dereference in the appid.sys driver
CVE-2024-21338HIGHbajo ataqueransomware05 may 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC1
FoxyProxys/CVE-2024-27956
CVE-2024-27956CRITICAL05 may 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC
Vignesh2712/Automation-for-Juniper-cve-2023-36845
CVE-2023-36845CRITICALbajo ataque04 may 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC1
Joomla! v4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMbajo ataque04 may 2024
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC1
Jenkins CVE-2024-23897: Arbitrary File Read Vulnerability
CVE-2024-23897CRITICALbajo ataqueransomware03 may 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
Bypass for CVE-2007-4559 Trellix patch
CVE-2007-4559CRITICAL03 may 2024
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RIESGO
abrir
GitHub PoC2
CVE-2024-21413 Microsoft Outlook RCE Exploit
CVE-2024-21413CRITICALbajo ataque03 may 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2024-27956 WORDPRESS RCE PLUGIN
CVE-2024-27956CRITICAL03 may 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC7
Exploit for Microsoft SmartScreen malicious execution (april 2024)
CVE-2024-29988HIGHbajo ataque03 may 2024
SmartScreen Prompt Security Feature Bypass Vulnerability
83RIESGO
abrir
GitHub PoC7
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
CVE-2024-4040CRITICALbajo ataque03 may 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC
ShellUnease/CVE-2024-34833-payroll-management-system-rce
CVE-2024-34833CRITICAL02 may 2024
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settin
48RIESGO
abrir
GitHub PoC
xsxtw/CVE-2019-0232
CVE-2019-023202 may 2024
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC
xsxtw/CVE-2022-26134
CVE-2022-26134CRITICALbajo ataqueransomware02 may 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC90
PoC for SQL Injection in CVE-2024-27956
CVE-2024-27956CRITICAL01 may 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC
tronghoang89/cve-2019-16113
CVE-2019-1611301 may 2024
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC
PoC for CVE-2023-32749 affecting Pydio Cells
CVE-2023-32749HIGH01 may 2024
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RIESGO
abrir
GitHub PoC
Neo-XeD/CVE-2024-33775
CVE-2024-33775CRITICAL01 may 2024
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a cr
48RIESGO
abrir
GitHub PoC
xsxtw/SpringFramework_CVE-2022-22965_RCE
CVE-2022-22965CRITICALbajo ataque01 may 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
anteriorpágina 227 / 456siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.