Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
76.313 exploits
VulnCheck XDB
infoleak
CVE-2024-8522CRITICAL19 sep 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RIESGO
abrir
GitHub PoC6
POC_CVE-2024-46256
CVE-2024-46256CRITICAL19 sep 2024
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RIESGO
abrir
GitHub PoC
safeer-accuknox/CrushFTP-cve-2024-4040-poc
CVE-2024-4040CRITICALbajo ataque18 sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC4
CVE-2022-23131 Zabbix Server SAML authentication exploit
CVE-2022-23131CRITICALbajo ataque18 sep 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALbajo ataque18 sep 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALbajo ataque18 sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC3
Client Implementation for the WatchGuard SSO Agent Protocol used for Security Research (CVE-2024-6592, CVE-2024-6593, CVE-2024-6594)
CVE-2024-6592CRITICAL17 sep 2024
WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL17 sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC2
The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads
CVE-2024-43160CRITICAL17 sep 2024
WordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability
63RIESGO
abrir
GitHub PoC2
0xAgun/CVE-2024-2876
CVE-2024-2876CRITICAL17 sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC3
CVE-2024-44000-LiteSpeed-Cache
CVE-2024-44000CRITICAL16 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
GitHub PoC
Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!
CVE-2021-3493HIGHbajo ataque16 sep 2024
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC49
This repository contains PoC for CVE-2024-7965. This is the vulnerability in the V8 that occurs only within ARM64.
CVE-2024-7965HIGHbajo ataque16 sep 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2016-1092416 sep 2024
The ebook-download plugin before 1.2 for WordPress has directory traversal.
43RIESGO
abrir
GitHub PoC16
CVE-2024-8190: Ivanti Cloud Service Appliance Command Injection
CVE-2024-8190HIGHbajo ataque16 sep 2024
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-44000CRITICAL16 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL16 sep 2024
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-8190HIGHbajo ataque16 sep 2024
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RIESGO
abrir
GitHub PoC4
Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption
CVE-2023-21716CRITICAL16 sep 2024
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC4
Server-Side Template Injection Exploit
CVE-2024-32651CRITICAL16 sep 2024
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RIESGO
abrir
GitHub PoC1
PoC code for vulnerability in webmod v0.48. Originally written in 2007, assigned CVE-2007-1260.
CVE-2007-126016 sep 2024
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-7965HIGHbajo ataque16 sep 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-27950MEDIUMbajo ataque15 sep 2024
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-6782CRITICAL15 sep 2024
Calibre Remote Code Execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALbajo ataque15 sep 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
GitHub PoC5
A Bash script for Kali Linux that exploits an iOS WebKit vulnerability (CVE-2020-27950) using Metasploit and ngrok. Automates payload delivery with a public URL via ngrok, checks for required tools, handles errors, and provides an easy way to crash browsers for educational purposes only.
CVE-2020-27950MEDIUMbajo ataque15 sep 2024
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-27564MEDIUM15 sep 2024
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-40711CRITICALbajo ataqueransomware15 sep 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RIESGO
abrir
GitHub PoC48
POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
CVE-2024-23692CRITICALbajo ataque15 sep 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
GitHub PoC2
dogucyber/WordPress-Exploit-CVE-2024-1071
CVE-2024-1071CRITICAL15 sep 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
anteriorpágina 346 / 2544siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.