Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.316exploits catalogados
34.835CVEs con explotación pública
24.695probados en laboratorio
76.316 exploits
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALbajo ataqueransomware09 sep 2024
Unauthenticated sensitive information disclosure
100RIESGO
abrir
GitHub PoC4
A proof of concept of the LFI vulnerability on aiohttp 3.9.1
CVE-2024-23334MEDIUM08 sep 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC7
A proof of concept exploit for SQLPad RCE (CVE-2022-0944).
CVE-2022-0944CRITICAL08 sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-29269HIGH08 sep 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM08 sep 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-44849CRITICAL07 sep 2024
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
75RIESGO
abrir
GitHub PoC
quick powershell script to fix cve-2024-38063
CVE-2024-38063CRITICAL07 sep 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC5
🔥 CVE-2024-44849 Exploit
CVE-2024-44849CRITICAL07 sep 2024
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
75RIESGO
abrir
GitHub PoC16
CVE-2024-44000 is a vulnerability in the LiteSpeed Cache plugin, a popular WordPress plugin. This vulnerability affects session management in LiteSpeed Cache, allowing attackers to gain unauthorized access to sensitive data.
CVE-2024-44000CRITICAL06 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
GitHub PoC
LiteSpeed Unauthorized Account Takeover
CVE-2024-44000CRITICAL06 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
GitHub PoC16
SPIP BigUp Plugin Unauthenticated RCE
CVE-2024-8517CRITICAL06 sep 2024
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir
GitHub PoC2
XSS to RCE in RenderTune v1.1.4 exploit
CVE-2024-25292CRITICAL06 sep 2024
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-44000CRITICAL06 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-44000CRITICAL06 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
Metasploit600
SPIP BigUp Plugin Unauthenticated RCE
CVE-2024-8517CRITICAL06 sep 2024
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-21887CRITICALbajo ataqueransomware06 sep 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-10149CRITICALbajo ataque06 sep 2024
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC
nteract 0.28.0 open redirect to RCE exploit
CVE-2024-22891CRITICAL06 sep 2024
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
48RIESGO
abrir
GitHub PoC
test POC for CVE-2019-10149
CVE-2019-10149CRITICALbajo ataque06 sep 2024
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC
deskfiler 1.2.3 Open Redirect exploit
CVE-2024-25291CRITICAL06 sep 2024
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALbajo ataque05 sep 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
GitHub PoC6
fru1ts/CVE-2024-44902
CVE-2024-44902CRITICAL05 sep 2024
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RIESGO
abrir
GitHub PoC
bryanqb07/CVE-2023-32315
CVE-2023-32315HIGHbajo ataque05 sep 2024
Openfire administration console authentication bypass
100RIESGO
abrir
GitHub PoC5
Research and PoC for CVE-2024-6386
CVE-2024-6386CRITICAL05 sep 2024
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
53RIESGO
abrir
GitHub PoC12
Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)
CVE-2024-28987CRITICALbajo ataque05 sep 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-44902CRITICAL05 sep 2024
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RIESGO
abrir
Metasploit600
Wordpress LiteSpeed Cache plugin cookie theft
CVE-2024-44000CRITICAL04 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
GitHub PoC1
This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.
CVE-2017-5638CRITICALbajo ataqueransomware04 sep 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC4
Masamuneee/CVE-2024-4367-Analysis
CVE-2024-4367MEDIUM04 sep 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-1212CRITICALbajo ataque04 sep 2024
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir
anteriorpágina 349 / 2544siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.