Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
76.313 exploits
VulnCheck XDB
initial-access
CVE-2024-45409CRITICAL07 oct 2024
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware07 oct 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM07 oct 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque07 oct 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC1
Automated Exploit for CVE-2020-6287
CVE-2020-6287CRITICALbajo ataque07 oct 2024
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
GitHub PoC1
CVE-2023-22527 | RCE using SSTI in Confluence
CVE-2023-22527CRITICALbajo ataqueransomware06 oct 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
GitHub PoC4
is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7)
CVE-2019-919306 oct 2024
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque06 oct 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware06 oct 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
GitHub PoC4
is a PoC tool demonstrating an exploit for a known vulnerability in the WebDAV component of IIS6
CVE-2017-7269CRITICALbajo ataque06 oct 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-919306 oct 2024
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-5016406 oct 2024
Apache Struts: File upload component had a directory traversal vulnerability
45RIESGO
abrir
GitHub PoC4
A simple Python script to test an off-by-one vulnerability in the OPIE library (CVE-2010-1938). This vulnerability affects certain FTP servers and may allow for Denial of Service (DoS) or arbitrary code execution.
CVE-2010-193805 oct 2024
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeB
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL05 oct 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM05 oct 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-51211CRITICAL05 oct 2024
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-45519CRITICALbajo ataque05 oct 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-43798HIGHbajo ataque05 oct 2024
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-38475CRITICALbajo ataque05 oct 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque05 oct 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC3
Python implementation of a tool for decrypting and encrypting sensitive data in Grafana, specifically addressing the vulnerabilities associated with CVE-2021-43798. Grafana encrypts all data source passwords using the AES algorithm with the secret_key found in the defaults.ini configuration file.
CVE-2021-43798HIGHbajo ataque05 oct 2024
Grafana path traversal
100RIESGO
abrir
GitHub PoC6
CVE-2024-26304 is a critical vulnerability (CVSS score of 9.8) affecting ArubaOS
CVE-2024-26304CRITICAL05 oct 2024
There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated r
60RIESGO
abrir
GitHub PoC139
Zimbra - Remote Command Execution (CVE-2024-45519)
CVE-2024-45519CRITICALbajo ataque05 oct 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir
GitHub PoC5
The CVE-2019-16172 Scanner is designed to check LimeSurvey instances for the stored XSS vulnerability.
CVE-2019-1617205 oct 2024
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2564604 oct 2024
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir
GitHub PoC2
Simple hash cracker for Apache Shiro hashes written in Golang. Useful for exploiting CVE-2024-4956.
CVE-2024-4956HIGH04 oct 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC
EuJin03/CVE-2021-4034-PoC
CVE-2021-4034HIGHbajo ataque04 oct 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC3
A Bash script designed to scan multiple domains for the CVE-2024-4577 vulnerability in PHP-CGI.
CVE-2024-4577CRITICALbajo ataqueransomware04 oct 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
RCE in pyload prior to 0.5.0b3.dev31.
CVE-2023-0297CRITICAL04 oct 2024
Code Injection in pyload/pyload
85RIESGO
abrir
GitHub PoC1
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
CVE-2024-7854CRITICAL04 oct 2024
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
63RIESGO
abrir
anteriorpágina 342 / 2544siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.