Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
76.496 exploits
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware29 ago 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware29 ago 2024
Information disclosure
100RIESGO
abrir
GitHub PoC7
Fully automated PoC - CVE-2024-25641 - RCE - Cacti < v1.2.26 🌵
CVE-2024-25641CRITICAL29 ago 2024
Cacti RCE vulnerability when importing packages
85RIESGO
abrir
GitHub PoC
LuisMateo1/Arbitrary-File-Read-CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware29 ago 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
In an era where digital security is crucial, a new vulnerability in OpenSSH, identified as CVE-2024-6387, has drawn the attention of system administrators and security professionals worldwide. Named "regreSSHion," this severe security flaw allows remote code execution (RCE) and could significant threat to the integrity of vulnerable systems.
CVE-2024-6387HIGH29 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC83
mistymntncop/CVE-2024-5274
CVE-2024-5274HIGHbajo ataque29 ago 2024
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
GitHub PoC
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
CVE-2024-7593CRITICALbajo ataque28 ago 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RIESGO
abrir
GitHub PoC6
This exploit will attempt to execute system commands on SPIP targets.
CVE-2024-7954CRITICAL28 ago 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
GitHub PoC7
potential memory corruption vulnerabilities in IPv6 networks.
CVE-2024-38063CRITICAL28 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC2
Remotely Exploiting The Kernel Via IPv6
CVE-2024-38063CRITICAL28 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC4
Windows TCP/IP IPv6(CVE-2024-38063)
CVE-2024-38063CRITICAL28 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC2
This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
CVE-2024-6387HIGH28 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC
Apache: a Mainstream Web Service Turned a Vector of Attack for Remote Code Execution
CVE-2021-41773HIGHbajo ataqueransomware28 ago 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL28 ago 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
GitHub PoC2
D0rDa4aN919/CVE-2023-22809-Exploiter
CVE-2023-22809HIGH28 ago 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC3
Apache OFBiz CVE-2024-38856
CVE-2024-38856HIGHbajo ataque28 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
GitHub PoC1
【Teedy 1.11】Account Takeover via XSS
CVE-2024-46278HIGH28 ago 2024
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
41RIESGO
abrir
VulnCheck XDB
local
CVE-2023-22809HIGH28 ago 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque27 ago 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALbajo ataque27 ago 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
Metasploit600
Moodle Remote Code Execution (CVE-2024-43425)
CVE-2024-43425HIGH27 ago 2024
Moodle: remote code execution via calculated question types
78RIESGO
abrir
GitHub PoC2
PoC for CVE-2024-25641 Authenticated RCE on Cacti v1.2.26
CVE-2024-25641CRITICAL27 ago 2024
Cacti RCE vulnerability when importing packages
85RIESGO
abrir
GitHub PoC1
Nuclei template to scan for Apache Ofbiz affecting versions before 18.12.15
CVE-2024-38856HIGHbajo ataque27 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
GitHub PoC
CVE-2023-4220 Chamilo Exploit
CVE-2023-4220HIGH27 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC10
CVE-2024-25641 - RCE Automated Exploit - Cacti 1.2.26
CVE-2024-25641CRITICAL27 ago 2024
Cacti RCE vulnerability when importing packages
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL27 ago 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir
GitHub PoC7
PoC for the CVE-2024 Litespeed Cache Privilege Escalation
CVE-2024-28000CRITICAL27 ago 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir
GitHub PoC4
Jelly Template Injection Vulnerability in ServiceNow | POC CVE-2024-4879
CVE-2024-4879CRITICALbajo ataque27 ago 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
GitHub PoC4
Mass scanner for CVE-2024-36401
CVE-2024-36401CRITICALbajo ataque27 ago 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC2
CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
CVE-2023-41425MEDIUM27 ago 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
anteriorpágina 354 / 2550siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.