Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
76.107 exploits
GitHub PoC
This repo contains both the exploit and the explaination of how this vulnerability is exploited
CVE-2019-1863411 dic 2024
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC
Cái này dựng lên với mục đích cho ae tham khảo, chê thì đừng có xem. :))))
CVE-2023-346011 dic 2024
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
GitHub PoC8
This PoC is targeting vulnerabilities in Palo Alto PAN-OS, specifically CVE-2024-0012 and CVE-2024-9474. This script automates the exploitation process, including payload creation, chunked delivery, and seamless command execution.
CVE-2024-0012CRITICALbajo ataqueransomware11 dic 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC
An example of a repo that would make use of the CVE-2024-32002
CVE-2024-32002CRITICAL11 dic 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
itform-fr/Zabbix---CVE-2024-42327
CVE-2024-42327CRITICAL11 dic 2024
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC2
Palo Alto Networks PAN-OS(CVE-2024-9474) POC
CVE-2024-9474MEDIUMbajo ataqueransomware11 dic 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
GitHub PoC1
KiviCare – Clinic & Patient Management System (EHR) WordPress Plugin Unauthenticated SQL Injection PoC
CVE-2024-11728HIGH11 dic 2024
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware11 dic 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMbajo ataqueransomware11 dic 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-50623CRITICALbajo ataqueransomware11 dic 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMbajo ataqueransomware11 dic 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALbajo ataqueransomware11 dic 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC1
CVE-2024-55557
CVE-2024-55557CRITICAL10 dic 2024
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti
48RIESGO
abrir
GitHub PoC1
Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp directory; script has been adjusted accordingly.
CVE-2022-37706HIGH10 dic 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC1
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
CVE-2024-12209CRITICAL09 dic 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RIESGO
abrir
GitHub PoC
A simple python script to test for CVE-2024-9441.
CVE-2024-9441CRITICAL09 dic 2024
Linear eMerge e3-Series Forgot Password Command Injection
60RIESGO
abrir
Metasploit600
Cleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution
CVE-2024-55956CRITICALbajo ataqueransomware09 dic 2024
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can impo
95RIESGO
abrir
GitHub PoC
Danyw24/CVE-2004-1561-Icecast-Header-Overwrite-buffer-overflow-RCE-2.0.1-Win32-
CVE-2004-156109 dic 2024
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
GitHub PoC
Jimmy01240397/CVE-2012-1823-Analyze
CVE-2012-1823CRITICALbajo ataque09 dic 2024
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC1
This repository is a proof of concept (POC) for CVE-2024-23334, demonstrating an attempt to replicate the bug in aiohttp that leads to Local File Inclusion (LFI).
CVE-2024-23334MEDIUM09 dic 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21389HIGH09 dic 2024
BuddyPress privilege escalation via REST API
61RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-12209CRITICAL09 dic 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM09 dic 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC
This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)
CVE-2024-23346CRITICAL09 dic 2024
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware08 dic 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server
CVE-2017-5638CRITICALbajo ataqueransomware08 dic 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC1
The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
CVE-2021-2301708 dic 2024
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir
GitHub PoC4
D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins
CVE-2024-23897CRITICALbajo ataqueransomware08 dic 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC3
POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method
CVE-2024-42327CRITICAL07 dic 2024
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC
Calibre Remote Code Execution
CVE-2024-6782CRITICAL07 dic 2024
Calibre Remote Code Execution
85RIESGO
abrir
anteriorpágina 320 / 2537siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.