Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
76.313 exploits
VulnCheck XDB
infoleak
CVE-2021-3129CRITICALbajo ataqueransomware31 oct 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
GodOfServer/CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware31 oct 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC5
CVE-2024-51567 is a Python PoC exploit targeting an RCE vulnerability in CyberPanel v2.3.6’s upgrademysqlstatus endpoint, bypassing CSRF protections.
CVE-2024-51567CRITICALbajo ataqueransomware31 oct 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir
GitHub PoC1
puckiestyle/CVE-2024-23113
CVE-2024-23113CRITICALbajo ataque31 oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir
GitHub PoC1
chsxthwik/CVE-2024-27954
CVE-2024-27954CRITICAL30 oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RIESGO
abrir
GitHub PoC2
cve-2024-38821
CVE-2024-38821CRITICAL30 oct 2024
Authorization Bypass of Static Resources in WebFlux Applications
48RIESGO
abrir
GitHub PoC2
sxyrxyy/CVE-2024-21320-POC
CVE-2024-21320MEDIUM30 oct 2024
Windows Themes Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
Writing one because the one I found isn't working
CVE-2023-41425MEDIUM30 oct 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-27954CRITICAL30 oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RIESGO
abrir
GitHub PoC1
CVE-2024-48359 PoC
CVE-2024-48359CRITICAL30 oct 2024
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parame
48RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-44258HIGH29 oct 2024
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-51378CRITICALbajo ataqueransomware29 oct 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27954CRITICAL29 oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RIESGO
abrir
GitHub PoC4
Automatic Plugin for WordPress < 3.92.1 Multiples Vulnerabilities
CVE-2024-27954CRITICAL29 oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RIESGO
abrir
GitHub PoC23
Exploit for CyberPanel Pre-Auth RCE via Command Injection
CVE-2024-51378CRITICALbajo ataqueransomware29 oct 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
GitHub PoC
It's Proof of Concept on CVE-2024-24919-POC , i made it after it's discoverd
CVE-2024-24919HIGHbajo ataqueransomware28 oct 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
0xDTC/Prestashop-CVE-2024-34716
CVE-2024-34716CRITICAL28 oct 2024
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RIESGO
abrir
Metasploit600
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
CVE-2024-28397MEDIUM28 oct 2024
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC2
Stack-Overflow on TendaAC8
CVE-2023-33669CRITICAL28 oct 2024
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct
48RIESGO
abrir
Metasploit600
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
CVE-2024-39205CRITICAL28 oct 2024
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RIESGO
abrir
Metasploit600
Prison Management System 1.0 Authenticated RCE via Unrestricted File Upload
CVE-2024-48594HIGH28 oct 2024
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the f
36RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware28 oct 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
Refurbish Chamilo LMS CVE-2023-4220 exploit written in bash
CVE-2023-4220HIGH27 oct 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
CVE-2023-41425 Refurbish
CVE-2023-41425MEDIUM27 oct 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CVE-2024-51567CRITICALbajo ataqueransomware27 oct 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir
Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CVE-2024-51568CRITICAL27 oct 2024
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RIESGO
abrir
Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CVE-2024-51378CRITICALbajo ataqueransomware27 oct 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
GitHub PoC
Refurbish
CVE-2022-0944CRITICAL27 oct 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH27 oct 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC18
Pyload RCE with js2py sandbox escape
CVE-2024-39205CRITICAL26 oct 2024
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RIESGO
abrir
anteriorpágina 335 / 2544siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.