Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
76.496 exploits
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware20 ago 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALbajo ataque20 ago 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-7928MEDIUM20 ago 2024
FastAdmin lang path traversal
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL20 ago 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-7928MEDIUM20 ago 2024
FastAdmin lang path traversal
53RIESGO
abrir
GitHub PoC
CVE-2023-29384 Auto Exploiter on WordPress Job Board and Recruitment Plugin
CVE-2023-29384CRITICAL20 ago 2024
WordPress WordPress Job Board and Recruitment Plugin – JobWP Plugin <= 2.0 is vulnerable to Arbitrary File Upload
48RIESGO
abrir
GitHub PoC
Reproducing the following CVEs with dockerfile:CVE-2024-33644 CVE-2024-34370 CVE-2024-22120
CVE-2024-33644CRITICAL20 ago 2024
WordPress Customify Site Library plugin <= 0.0.9 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-27925HIGHbajo ataqueransomware19 ago 2024
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-21587CRITICALbajo ataqueransomware19 ago 2024
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RIESGO
abrir
GitHub PoC1
jeyabalaji711/CVE-2024-42919
CVE-2024-42919CRITICAL19 ago 2024
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
48RIESGO
abrir
GitHub PoC
adobe commerce
CVE-2024-34102CRITICALbajo ataque19 ago 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
PoC
CVE-2022-27925HIGHbajo ataqueransomware19 ago 2024
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir
GitHub PoC
s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH
CVE-2024-6387HIGH19 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
anmolksachan/CVE-2020-2733
CVE-2020-2733CRITICAL19 ago 2024
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics)
68RIESGO
abrir
GitHub PoC
dweger-scripts/CVE-2024-38063-Remediation
CVE-2024-38063CRITICAL19 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
Poc for cve-2024-38063
CVE-2024-38063CRITICAL18 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
Chamilo LMS Unauthenticated Big Upload File that allows remote code execution
CVE-2023-4220HIGH18 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
PoC
CVE-2022-37706HIGH18 ago 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC
WTN-arny/CVE-2024-37085
CVE-2024-37085MEDIUMbajo ataqueransomware18 ago 2024
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RIESGO
abrir
GitHub PoC
CVE-2024-7094 Vulnerability checker
CVE-2024-7094CRITICAL18 ago 2024
JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.6 - Unauthenticated PHP Code Injection to Remote Code Execution
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque18 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
GitHub PoC1
Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15
CVE-2024-38856HIGHbajo ataque18 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH18 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-38475CRITICALbajo ataque18 ago 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RIESGO
abrir
GitHub PoC16
p0in7s/CVE-2024-38475
CVE-2024-38475CRITICALbajo ataque18 ago 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RIESGO
abrir
GitHub PoC
Comodo
CVE-2018-1743117 ago 2024
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir
GitHub PoC
POC
CVE-2024-32002CRITICAL17 ago 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC87
Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.
CVE-2024-38063CRITICAL17 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
CVE-2024-4577 Exploits
CVE-2024-4577CRITICALbajo ataqueransomware17 ago 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware17 ago 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
anteriorpágina 357 / 2550siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.