Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
76.107 exploits
VulnCheck XDB
initial-access
CVE-2024-56145CRITICALbajo ataque20 dic 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-27956CRITICAL20 dic 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC
Import Export For WooCommerce <= 1.5 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2024-54262CRITICAL19 dic 2024
WordPress Import Export For WooCommerce plugin <= 1.6.2 - Arbitrary File Upload vulnerability
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-12025HIGH19 dic 2024
Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection
56RIESGO
abrir
Metasploit600
Craft CMS Twig Template Injection RCE via FTP Templates Path
CVE-2024-56145CRITICALbajo ataque19 dic 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware19 dic 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC
Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation
CVE-2024-54369CRITICAL19 dic 2024
WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
48RIESGO
abrir
GitHub PoC3
test code for cve-2024-6387
CVE-2024-6387HIGH19 dic 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
yiliufeng168/CVE-2024-50379-POC
CVE-2024-50379CRITICAL19 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC1
webmin or minisever RCE
CVE-2019-15107CRITICALbajo ataqueransomware19 dic 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
Metasploit600
Windows Cloud File Mini Filer Driver Heap Overflow
CVE-2024-30085HIGH19 dic 2024
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2023-4966-exploit
CVE-2023-4966CRITICALbajo ataqueransomware18 dic 2024
Unauthenticated sensitive information disclosure
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2009-226518 dic 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC1
Adobe ColdFusion 8 - Remote Command Execution (RCE)
CVE-2009-226518 dic 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir
GitHub PoC2
dustblessnotdust/CVE-2024-53677-S2-067-thread
CVE-2024-53677CRITICAL18 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC4
v3153/CVE-2024-50379-POC
CVE-2024-50379CRITICAL18 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC3
A Docker-based environment to reproduce the CVE-2024-53677 vulnerability in Apache Struts 2.
CVE-2024-53677CRITICAL17 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC3
yangyanglo/CVE-2024-53677
CVE-2024-53677CRITICAL17 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC6
Proof of concept (POC) for CVE-2024-45337
CVE-2024-45337CRITICAL17 dic 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RIESGO
abrir
GitHub PoC1
An example project that showcases golang code vulnerable to CVE-2024-45337
CVE-2024-45337CRITICAL17 dic 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL17 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2024-12356CRITICALbajo ataque16 dic 2024
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
95RIESGO
abrir
VulnCheck XDB
local
CVE-2024-49039HIGHbajo ataqueransomware16 dic 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RIESGO
abrir
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2025-1094HIGH16 dic 2024
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware16 dic 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
The EXP/POC of CVE-2019-12725
CVE-2019-1272516 dic 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC
redspy-sec/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware16 dic 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1272516 dic 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
anteriorpágina 318 / 2537siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.