Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
13.654 exploits
GitHub PoC1
CVE-2023-6875 exploit written for Xakep.Ru
CVE-2023-6875CRITICAL05 feb 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir
GitHub PoC
semcms存在SQL注入(CVE-2024-25422 )
CVE-2024-25422CRITICAL04 feb 2024
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive info
48RIESGO
abrir
GitHub PoC1
GoAnywhere MFT
CVE-2024-0204CRITICAL04 feb 2024
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir
GitHub PoC1
Triggering the famous libweb 0day vuln with libfuzzer
CVE-2023-4863HIGHbajo ataque04 feb 2024
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC
Shellshock exploit (CVE-2014-6271)
CVE-2014-6271CRITICALbajo ataque04 feb 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC2
wechicken456/CVE-2021-4034-CTF-writeup
CVE-2021-4034HIGHbajo ataque04 feb 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
xMr110/CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque04 feb 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC5
Exploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite
CVE-2019-2215HIGHbajo ataque04 feb 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC
WLXQqwer/Jenkins-CVE-2024-23897-
CVE-2024-23897CRITICALbajo ataqueransomware04 feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC22
Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)
CVE-2024-23897CRITICALbajo ataqueransomware04 feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
CharonDefalt/Juniper-exploit-CVE-2023-36845
CVE-2023-36845CRITICALbajo ataque03 feb 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC27
CVE-2024-21893 to CVE-2024-21887 Exploit Toolkit
CVE-2024-21893HIGHbajo ataqueransomware03 feb 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RIESGO
abrir
GitHub PoC94
CVE-2024-21893: SSRF Vulnerability in Ivanti Connect Secure
CVE-2024-21893HIGHbajo ataqueransomware02 feb 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RIESGO
abrir
GitHub PoC
Trinadh465/external_zlib_android-6.0.1_r22_CVE-2022-37434
CVE-2022-37434CRITICAL02 feb 2024
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header
53RIESGO
abrir
GitHub PoC
Trinadh465/external_zlib_CVE-2022-37434
CVE-2022-37434CRITICAL02 feb 2024
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header
53RIESGO
abrir
GitHub PoC
CVE-2023-22527 Batch scanning
CVE-2023-22527CRITICALbajo ataqueransomware02 feb 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
GitHub PoC
cyb3rzest/Juniper-Bug-Automation-CVE-2023-36845
CVE-2023-36845CRITICALbajo ataque01 feb 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC1
PoC for Jenkins CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware01 feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC2
Es una vulnerabilidad para escalar privilegios en linux.
CVE-2019-13272HIGHbajo ataque31 ene 2024
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC
m-y-mo: https://github.com/github/securitylab/tree/main/SecurityExploits/Chrome/v8/CVE-2021-30632
CVE-2021-30632HIGHbajo ataque31 ene 2024
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RIESGO
abrir
GitHub PoC1
POC about Web3 – Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass Wordpress plugin
CVE-2023-6036CRITICAL31 ene 2024
Web3 – Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass
48RIESGO
abrir
GitHub PoC1
Juniper RCE (Remote Code Execution) CVE-2023-36845 is a vulnerability that has been identified within Juniper's software. This particular flaw allows for remote code execution, meaning an attacker could run arbitrary code on a system without needing physical access to the device.
CVE-2023-36845CRITICALbajo ataque30 ene 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC19
Simple Automation script for juniper cve-2023-36845
CVE-2023-36845CRITICALbajo ataque29 ene 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC5
CVE-2023-41892 Reverse Shell
CVE-2023-41892CRITICAL29 ene 2024
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC5
Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE
CVE-2024-23897CRITICALbajo ataqueransomware29 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC1
jopraveen/CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware29 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC17
This repository presents a proof-of-concept of CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware28 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
CVE-2024-23897CRITICALbajo ataqueransomware28 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC1
GitLab CVE-2023-7028
CVE-2023-7028CRITICALbajo ataque28 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
GitHub PoC
Samba 3.0.0 - 3.0.25rc3
CVE-2007-244728 ene 2024
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
anteriorpágina 240 / 456siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.