Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
76.107 exploits
GitHub PoC83
tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp
CVE-2024-50379CRITICAL23 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC1
WonderCMS v3.2.0 - v3.4.2 XSS to RCE exploit
CVE-2023-41425MEDIUM22 dic 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
GitHub PoC4
CVE-2024-56145 SSTI to RCE - twig templates
CVE-2024-56145CRITICALbajo ataque22 dic 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-26229HIGH22 dic 2024
Windows CSC Service Elevation of Privilege Vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-56145CRITICALbajo ataque22 dic 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-12149CRITICALbajo ataqueransomware21 dic 2024
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC2
Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privileges and locate the flag stored behind the windows security
CVE-2017-0144HIGHbajo ataqueransomware21 dic 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-39914CRITICAL21 dic 2024
FOG has a command injection in /fog/management/export.php?filename=
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque21 dic 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-27292HIGH21 dic 2024
Docassemble unauthorized access through URL manipulation
68RIESGO
abrir
GitHub PoC
Mitel MiCollab 企业协作平台 任意文件读取漏洞(CVE-2024-41713)由于Mitel MiCollab软件的 NuPoint 统一消息 (NPM) 组件中存在身份验证绕过漏洞,并且输入验证不足,未经身份验证的远程攻击者可利用该漏洞执行路径遍历攻击,成功利用可能导致未授权访问、破坏或删除用户的数据和系统配置。影响范围:version < MiCollab 9.8 SP2 (9.8.2.12)
CVE-2024-41713CRITICALbajo ataqueransomware21 dic 2024
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
GitHub PoC
zesnd/cve-2017-12149
CVE-2017-12149CRITICALbajo ataqueransomware21 dic 2024
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC
cve-2024-CVE-2024-41713
CVE-2024-41713CRITICALbajo ataqueransomware21 dic 2024
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
GitHub PoC
zesnd/CVE-2020-14882-POC
CVE-2020-14882CRITICALbajo ataque21 dic 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC1
HFS2.3未经身份验证的远程代码执行(CVE-2024-23692)
CVE-2024-23692CRITICALbajo ataque21 dic 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
GitHub PoC
FOG Project CVE-2024-39914 命令执行漏洞
CVE-2024-39914CRITICAL21 dic 2024
FOG has a command injection in /fog/management/export.php?filename=
68RIESGO
abrir
GitHub PoC2
Check-Point安全网关任意文件读取漏洞(CVE-2024-24919)
CVE-2024-24919HIGHbajo ataqueransomware21 dic 2024
Information disclosure
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-41713CRITICALbajo ataqueransomware21 dic 2024
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-0144HIGHbajo ataqueransomware21 dic 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-41713CRITICALbajo ataqueransomware21 dic 2024
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
GitHub PoC5
Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.
CVE-2023-40028MEDIUM21 dic 2024
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir
GitHub PoC57
RCE through a race condition in Apache Tomcat
CVE-2024-50379CRITICAL21 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALbajo ataque21 dic 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware21 dic 2024
Information disclosure
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-27956CRITICAL20 dic 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC22
Apache Tomcat(CVE-2024-50379)条件竞争致远程代码执行漏洞批量检测脚本
CVE-2024-50379CRITICAL20 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC1
CVE-2024-50379 is a critical vulnerability affecting multiple versions of Apache Tomcat, an open source web server and servlet container widely used for deploying Java-based web applications. The vulnerability arises from a Time-of-Use (TOCTOU) race condition that occurs when compiling JavaServer Pages (JSPs).
CVE-2024-50379CRITICAL20 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC6
CVE-2024-0132 – Fully Weaponized NVIDIA Container Toolkit Exploit
CVE-2024-0132CRITICAL20 dic 2024
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RIESGO
abrir
GitHub PoC2
Repositorio para alojar un template de Nuclei para probar el CVE-2024-50379 (en fase de prueba)
CVE-2024-50379CRITICAL20 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC
Yaml PoC rule for fscan.
CVE-2024-27956CRITICAL20 dic 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
anteriorpágina 317 / 2537siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.