Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
76.313 exploits
VulnCheck XDB
remote-with-credentials
CVE-2023-20198CRITICALbajo ataque22 nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC2
CVE-2024-0012批量检测脚本
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27130HIGH22 nov 2024
QTS, QuTS hero
53RIESGO
abrir
GitHub PoC
CVE-2024-0012是Palo Alto Networks PAN-OS软件中的一个身份验证绕过漏洞。该漏洞允许未经身份验证的攻击者通过网络访问管理Web界面,获取PAN-OS管理员权限,从而执行管理操作、篡改配置,或利用其他需要身份验证的特权提升漏洞(如CVE-2024-9474)
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC
punitdarji/Paloalto-CVE-2024-0012
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21626HIGH22 nov 2024
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-45519CRITICALbajo ataque22 nov 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALbajo ataque22 nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir
GitHub PoC
Broken Authentication in Wordpress plugin (Wawp Plugin < 3.0.18)
CVE-2024-52475CRITICAL22 nov 2024
WordPress Wawp plugin < 3.0.18 - Account Takeover vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALbajo ataqueransomware22 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-29442HIGH22 nov 2024
Authentication bypass
68RIESGO
abrir
GitHub PoC1
This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific version (`6.0.2.6`) and marks the site as vulnerable if found. The results are saved in a file (`vuln.txt`) for further analysis.
CVE-2024-10508CRITICAL21 nov 2024
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
48RIESGO
abrir
GitHub PoC2
This tool scans WordPress websites for vulnerabilities in the WP Time Capsule plugin related to CVE-2024-8856. It identifies plugin versions below 1.22.22 as vulnerable and logs results to vuln.txt. Simple and efficient, it helps security researchers and admins detect and address risks quickly.
CVE-2024-8856CRITICAL21 nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALbajo ataqueransomware21 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
Metasploit600
mySCADA myPRO Manager Unauthenticated Command Injection (CVE-2024-47407)
CVE-2024-47407CRITICAL21 nov 2024
mySCADA myPRO OS Command Injection
55RIESGO
abrir
Metasploit600
Pandora FMS authenticated command injection leading to RCE via LDAP using default DB password
CVE-2024-11320MEDIUM21 nov 2024
Command Injection leading to RCE via LDAP Misconfiguration
50RIESGO
abrir
GitHub PoC1
This is POC of CVE-2024-29671
CVE-2024-29671CRITICAL21 nov 2024
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code vi
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMbajo ataqueransomware20 nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALbajo ataqueransomware20 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC
CVE-2023-28354
CVE-2023-28354CRITICAL20 nov 2024
An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against aff
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL20 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC
FAFAF
CVE-2018-15473MEDIUM20 nov 2024
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC1
PANW NGFW CVE-2024-0012
CVE-2024-0012CRITICALbajo ataqueransomware20 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC
POC for CVE-2024-10924 written in Python
CVE-2024-10924CRITICAL20 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC
GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization
CVE-2024-6330CRITICAL20 nov 2024
GEO my WordPress < 4.4.0.2 - Unauthenticated RCE via LFI
48RIESGO
abrir
GitHub PoC
CVE-2024-52316 - Apache Tomcat Authentication Bypass Vulnerability
CVE-2024-52316CRITICAL20 nov 2024
Apache Tomcat: Authentication bypass when using Jakarta Authentication API
48RIESGO
abrir
GitHub PoC3
Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164
CVE-2024-10924CRITICAL20 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC
PoC for PAN-OS Exploit
CVE-2024-9474MEDIUMbajo ataqueransomware20 nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
GitHub PoC19
Exploits Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924).
CVE-2024-10924CRITICAL19 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC
wudidwo/CVE-2017-12615-poc
CVE-2017-12615HIGHbajo ataqueransomware19 nov 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
anteriorpágina 329 / 2544siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.