Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
76.107 exploits
GitHub PoC3
CVE-2023-40028 PoC Exploit
CVE-2023-40028MEDIUM28 dic 2024
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir
GitHub PoC
Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE
CVE-2024-8069MEDIUMbajo ataque28 dic 2024
Limited remote code execution with privilege of a NetworkService Account access
68RIESGO
abrir
GitHub PoC
Nxploited/CVE-2024-9933
CVE-2024-9933CRITICAL27 dic 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RIESGO
abrir
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48457HIGH27 dic 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
36RIESGO
abrir
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48455LOW27 dic 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
23RIESGO
abrir
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48456HIGH27 dic 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
41RIESGO
abrir
GitHub PoC
Testing the latset Apache Tomcat CVE-2024-50379 Vuln
CVE-2024-50379CRITICAL26 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC2
Drupal CVE-2024-45440
CVE-2024-45440MEDIUM26 dic 2024
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash
48RIESGO
abrir
GitHub PoC
AleksaZatezalo/CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque26 dic 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2291126 dic 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque26 dic 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC
Malware Analysis CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware26 dic 2024
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC
yoohhuu/Rocket-Chat-3.12.1-PoC-CVE-2021-22911-
CVE-2021-2291126 dic 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC1
UnionTech-Software/libtheora-CVE-2024-56431-PoC
CVE-2024-56431CRITICAL25 dic 2024
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: th
48RIESGO
abrir
GitHub PoC
A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1
CVE-2024-23334MEDIUM25 dic 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM25 dic 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC5
WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本
CVE-2024-9047CRITICAL25 dic 2024
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RIESGO
abrir
GitHub PoC4
This repository contains a Python script designed to exploit CVE-2024-50379, a vulnerability that allows attackers to upload a JSP shell to a vulnerable server and execute arbitrary commands remotely. This exploit is particularly useful when the /uploads directory is either unprotected or not present on the target server.
CVE-2024-50379CRITICAL25 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-9047CRITICAL25 dic 2024
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL24 dic 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC3
Unauthenticated Local File Inclusion
CVE-2024-12209CRITICAL24 dic 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALbajo ataque24 dic 2024
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-920624 dic 2024
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-12209CRITICAL24 dic 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RIESGO
abrir
GitHub PoC1
The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload.
CVE-2024-9290CRITICAL24 dic 2024
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
GitHub PoC
A PoC exploit for CVE-2024-10914 - D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL24 dic 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC83
tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp
CVE-2024-50379CRITICAL23 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC1
CVE-2024-50379利用
CVE-2024-50379CRITICAL23 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-50623CRITICALbajo ataqueransomware23 dic 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RIESGO
abrir
GitHub PoC
hiteshpatra/CVE-2024-53677
CVE-2024-53677CRITICAL23 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
anteriorpágina 316 / 2537siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.