Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
13.654 exploits
GitHub PoC1
Proof of Concept for CVE-2024-20767. Arbitrary file read from Adobe ColdFusion
CVE-2024-20767HIGHbajo ataque26 mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC1
404fu/CVE-2022-26134-POC
CVE-2022-26134CRITICALbajo ataqueransomware26 mar 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC10
Exploit Toolkit for Adobe ColdFusion CVE-2024-20767 Vulnerability
CVE-2024-20767HIGHbajo ataque26 mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC9
evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)
CVE-2023-38831HIGHbajo ataqueransomware25 mar 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
Madan301/CVE-2024-2054
CVE-2024-2054CRITICAL25 mar 2024
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RIESGO
abrir
GitHub PoC2
Part of my cybersecurity thesis consists in exploring and exploiting this vulnerability.
CVE-2021-3560HIGHbajo ataque24 mar 2024
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
CharonDefalt/WordPress--CVE-2022-21661
CVE-2022-21661HIGH24 mar 2024
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC13
0xyassine/CVE-2023-40028
CVE-2023-40028MEDIUM23 mar 2024
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir
GitHub PoC1
exploit CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware23 mar 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
sxyrxyy/CVE-2024-1709-ConnectWise-ScreenConnect-Authentication-Bypass
CVE-2024-1709CRITICALbajo ataqueransomware22 mar 2024
Authentication bypass using an alternate path or channel
100RIESGO
abrir
GitHub PoC
Nhom6KTLT/CVE-2010-3124
CVE-2010-312422 mar 2024
Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possib
28RIESGO
abrir
GitHub PoC2
XenoM0rph97/CVE-2024-30896
CVE-2024-30896CRITICAL22 mar 2024
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut
48RIESGO
abrir
GitHub PoC6
it's a CVE-2023-28252 (Patched), but feel free to use it for check any outdated software or reseach
CVE-2023-28252HIGHbajo ataqueransomware21 mar 2024
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
JolynNgSC/Zerologon_CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware21 mar 2024
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
Lilly-dox/Exploit-CVE-2023-22518
CVE-2023-22518CRITICALbajo ataqueransomware21 mar 2024
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir
GitHub PoC
Practice POC scripting in Tryhackme’s intro poc scripting room (For Linux)
CVE-2012-298221 mar 2024
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
GitHub PoC130
Windows Kernel Pool (clfs.sys) Corruption Privilege Escalation
CVE-2023-36424HIGHbajo ataque21 mar 2024
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC8
POC code according to trendmicro's research
CVE-2024-21412HIGHbajo ataqueransomware21 mar 2024
Internet Shortcut Files Security Feature Bypass Vulnerability
93RIESGO
abrir
GitHub PoC1
Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.
CVE-2023-23397CRITICALbajo ataque20 mar 2024
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC2448
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
CVE-2024-1086HIGHbajo ataqueransomware20 mar 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC19
Unauthenticated Command Injection In Progress Kemp LoadMaster
CVE-2024-1212CRITICALbajo ataque19 mar 2024
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir
GitHub PoC1
A vuln about csapp.
CVE-2024-28515CRITICAL19 mar 2024
Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary cod
48RIESGO
abrir
GitHub PoC27
aiohttp LFI (CVE-2024-23334)
CVE-2024-23334MEDIUM19 mar 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC20
A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1
CVE-2024-23334MEDIUM18 mar 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC3
Vulnerability in PHP Phar files, due to buffer overflow, arises from insufficient length checks on file names within the Phar archive. Malicious actors can craft Phar files with long file names, leading to buffer overflow and potential execution of malicious code or data leakage. This vulnerability can be exploited for code execution CVE-2023-3824
CVE-2023-3824CRITICAL18 mar 2024
Buffer overflow and overread in phar_dir_read()
48RIESGO
abrir
GitHub PoC1
CVE-2024-1071
CVE-2024-1071CRITICAL18 mar 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
GitHub PoC1
Matrexdz/CVE-2024-1071-Docker
CVE-2024-1071CRITICAL18 mar 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
GitHub PoC1
K3ysTr0K3R/CVE-2017-12617-EXPLOIT
CVE-2017-12617HIGHbajo ataque18 mar 2024
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2024-25153.
CVE-2024-25153CRITICAL18 mar 2024
Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
60RIESGO
abrir
GitHub PoC54
Fortinet FortiClient EMS SQL Injection
CVE-2023-48788CRITICALbajo ataqueransomware18 mar 2024
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio
100RIESGO
abrir
anteriorpágina 235 / 456siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.