Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
76.313 exploits
GitHub PoC
pedrochalegre7/CVE-2024-4367-pdf-sample
CVE-2024-4367MEDIUM06 nov 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC25
CVE-2024-4577 RCE PoC
CVE-2024-4577CRITICALbajo ataqueransomware06 nov 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
pbj2647/CVE-2023-25813
CVE-2023-25813CRITICAL06 nov 2024
SQL Injection via replacements in sequelize
48RIESGO
abrir
GitHub PoC6
WP REST API FNS <= 1.0.0 - Privilege Escalation
CVE-2024-49328CRITICAL06 nov 2024
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RIESGO
abrir
GitHub PoC
1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover
CVE-2024-50478CRITICAL05 nov 2024
WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
48RIESGO
abrir
GitHub PoC
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
CVE-2024-9933CRITICAL05 nov 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RIESGO
abrir
GitHub PoC3
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-9932CRITICAL05 nov 2024
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC2
Meetup <= 0.1 - Authentication Bypass via Account Takeover
CVE-2024-50483CRITICAL05 nov 2024
WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability
48RIESGO
abrir
GitHub PoC
Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-50482CRITICAL05 nov 2024
WordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque05 nov 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC4
This repository contains a Crystallographic Information File (CIF) intended for use on the "Chemistry" machine on Hack The Box (HTB).
CVE-2024-23346CRITICAL05 nov 2024
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-2907805 nov 2024
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-50498CRITICAL04 nov 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir
GitHub PoC3
WP Query Console <= 1.0 - Unauthenticated Remote Code Execution
CVE-2024-50498CRITICAL04 nov 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir
GitHub PoC
Signup Page <= 1.0 - Unauthenticated Arbitrary Options Update
CVE-2024-50475CRITICAL04 nov 2024
WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability
48RIESGO
abrir
GitHub PoC
GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update
CVE-2024-50476CRITICAL04 nov 2024
WordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability
48RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-37383MEDIUMbajo ataque03 nov 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RIESGO
abrir
GitHub PoC
ahmetramazank/CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware03 nov 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)
CVE-2024-37383MEDIUMbajo ataque03 nov 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RIESGO
abrir
GitHub PoC
POC firewall with rules designed to detect and block Spring4Shell vulnerability (CVE-2022-22965) exploit
CVE-2022-22965CRITICALbajo ataque02 nov 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH02 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
77Philly/CVE-2024-7456scripts
CVE-2024-7456CRITICAL02 nov 2024
SQL Injection in lunary-ai/lunary
48RIESGO
abrir
GitHub PoC1
JAckLosingHeart/CVE-2024-51132-POC
CVE-2024-51132CRITICAL02 nov 2024
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o
48RIESGO
abrir
GitHub PoC
CVE-2023-4220 Chamilo Exploit
CVE-2023-4220HIGH02 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC2
wp/ultimate-member - SQL Injection Vulnerability Exploit Script.
CVE-2024-1071CRITICAL01 nov 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-1071CRITICAL01 nov 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2015-925101 nov 2024
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RIESGO
abrir
GitHub PoC
GodOfServer/CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware31 oct 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23113CRITICALbajo ataque31 oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir
GitHub PoC
hualy13/CVE-2019-0708-Check
CVE-2019-0708CRITICALbajo ataqueransomware31 oct 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
anteriorpágina 334 / 2544siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.