Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
76.107 exploits
VulnCheck XDB
local
CVE-2024-49138HIGHbajo ataque15 ene 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC270
POC exploit for CVE-2024-49138
CVE-2024-49138HIGHbajo ataque15 ene 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC1
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
CVE-2024-21887CRITICALbajo ataqueransomware14 ene 2025
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir
GitHub PoC1
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
CVE-2023-46805HIGHbajo ataqueransomware14 ene 2025
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir
GitHub PoC1
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
CVE-2025-0282CRITICALbajo ataqueransomware14 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
Metasploit600
GestioIP 3.5.7 Remote Command Execution
CVE-2024-48760CRITICAL14 ene 2025
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke
75RIESGO
abrir
GitHub PoC1
CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins, risking RCE, SQLi, XSS, and backdoors.
CVE-2024-11972CRITICAL13 ene 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir
Metasploit300
Car Rental System 1.0 File Upload RCE (Authenticated)
CVE-2024-57487MEDIUM13 ene 2025
In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types a
28RIESGO
abrir
GitHub PoC1
Partners <= 0.2.0 - Unauthenticated PHP Object Injection
CVE-2024-56059CRITICAL13 ene 2025
WordPress Partners plugin <= 0.2.0 - PHP Object Injection vulnerability
48RIESGO
abrir
GitHub PoC1
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
CVE-2024-10571CRITICAL13 ene 2025
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
63RIESGO
abrir
GitHub PoC1
VRPConnector <= 2.0.1 - Unauthenticated PHP Object Injection
CVE-2024-56058CRITICAL13 ene 2025
WordPress VRPConnector plugin <= 2.0.1 - PHP Object Injection vulnerability
48RIESGO
abrir
GitHub PoC3
CVE-2024-35250 PoC - Optimized & Condensed Form of Varwara's PoC
CVE-2024-35250HIGHbajo ataque13 ene 2025
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir
VulnCheck XDB
local
CVE-2024-35250HIGHbajo ataque13 ene 2025
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-11972CRITICAL13 ene 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-10571CRITICAL13 ene 2025
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
63RIESGO
abrir
GitHub PoC4
# CVE-2025-0282: Remote Code Execution Vulnerability in [StorkS]
CVE-2025-0282CRITICALbajo ataqueransomware12 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-50603CRITICALbajo ataque12 ene 2025
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RIESGO
abrir
GitHub PoC1
Subscribe to Category <= 2.7.4 - Unauthenticated SQL Injection
CVE-2023-32590CRITICAL12 ene 2025
WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to SQL Injection
63RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21338HIGHbajo ataqueransomware12 ene 2025
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-3605CRITICAL12 ene 2025
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10586CRITICAL12 ene 2025
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-9707CRITICAL12 ene 2025
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RIESGO
abrir
GitHub PoC2
kcfg bypass example - CVE-2024-21338
CVE-2024-21338HIGHbajo ataqueransomware12 ene 2025
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
Metasploit300
SimpleHelp Path Traversal Vulnerability CVE-2024-57727
CVE-2024-57727CRITICALbajo ataqueransomware12 ene 2025
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RIESGO
abrir
GitHub PoC
he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)
CVE-2024-9707CRITICAL12 ene 2025
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RIESGO
abrir
GitHub PoC1
RSVP ME <= 1.9.9 - Unauthenticated SQL Injection
CVE-2024-50491CRITICAL12 ene 2025
WordPress RSVP ME plugin <= 1.9.9 - SQL Injection vulnerability
48RIESGO
abrir
GitHub PoC17
CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection
CVE-2024-50603CRITICALbajo ataque12 ene 2025
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RIESGO
abrir
GitHub PoC1
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
CVE-2024-3605CRITICAL12 ene 2025
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
63RIESGO
abrir
GitHub PoC
Nxploited/CVE-2024-10586-Poc
CVE-2024-10586CRITICAL12 ene 2025
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RIESGO
abrir
GitHub PoC1
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
CVE-2024-12877CRITICAL11 ene 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RIESGO
abrir
anteriorpágina 312 / 2537siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.