Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
76.496 exploits
GitHub PoC
PoC about CVE-2024-27198
CVE-2024-27198CRITICALbajo ataqueransomware16 ago 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALbajo ataqueransomware16 ago 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
Metasploit600
SPIP Unauthenticated RCE via porte_plume Plugin
CVE-2024-7954CRITICAL16 ago 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL15 ago 2024
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC7
CVE-2024-38077,仅支持扫描测试~
CVE-2024-38077CRITICAL15 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
MahdiOsman/CVE-2018-15473-SNMPv1-2-Community-String-Vulnerability-Testing
CVE-2018-15473MEDIUM15 ago 2024
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC13
mitigation script by disabling ipv6 of all interfaces
CVE-2024-38063CRITICAL15 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
1amthebest1/CVE-2023-27372
CVE-2023-27372CRITICAL15 ago 2024
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC1
An issue in Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
CVE-2024-42850CRITICAL15 ago 2024
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity
48RIESGO
abrir
Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
CVE-2024-45256CRITICAL15 ago 2024
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overw
43RIESGO
abrir
Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
CVE-2024-45257HIGH15 ago 2024
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi
36RIESGO
abrir
VulnCheck XDB
local
CVE-2024-30051HIGHbajo ataqueransomware14 ago 2024
Windows DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC125
fortra/CVE-2024-30051
CVE-2024-30051HIGHbajo ataqueransomware14 ago 2024
Windows DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALbajo ataque14 ago 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-22120CRITICAL14 ago 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RIESGO
abrir
VulnCheck XDB
local
CVE-2023-22809HIGH14 ago 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC
Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
CVE-2024-4879CRITICALbajo ataque14 ago 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
GitHub PoC
JolyIrsb/CVE-2024-4956
CVE-2024-4956HIGH14 ago 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC3
This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where I could use gopher to make internal requests on Zabbix vulnerable to RCE.
CVE-2024-22120CRITICAL14 ago 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RIESGO
abrir
GitHub PoC3
This is my exploit for CVE-2024-22120, which involves an SSRF vulnerability inside an XXE with a Gopher payload.
CVE-2024-22120CRITICAL13 ago 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RIESGO
abrir
GitHub PoC3
K7 Ultimate Security < v17.0.2019 "K7RKScan.sys" Null Pointer Dereference PoC
CVE-2024-36424MEDIUM13 ago 2024
K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-34102CRITICALbajo ataque13 ago 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
jFriedli/CVE-2023-3897
CVE-2023-3897MEDIUM13 ago 2024
Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page
33RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-22120CRITICAL13 ago 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RIESGO
abrir
GitHub PoC4
Adobe Commerce XXE exploit
CVE-2024-34102CRITICALbajo ataque13 ago 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL12 ago 2024
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-6308MEDIUM12 ago 2024
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at
60RIESGO
abrir
GitHub PoC
This repository contains detailed documentation and code related to the exploitation, detection, and mitigation of two significant vulnerabilities: CVE-2020-0796 (SMBGhost) and Print Spooler.
CVE-2020-0796CRITICALbajo ataqueransomware12 ago 2024
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
This script is a proof-of-concept exploit for pfBlockerNG <= 2.1.4_26 that allows for remote code execution. It takes a single target URL or a list of URLs, tries to upload a shell using multiple payloads, executes a command, and then deletes the shell.
CVE-2022-31814CRITICAL12 ago 2024
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
GitHub PoC
CVE-2024-37085 unauthenticated shell upload to full administrator on domain-joined esxi hypervisors.
CVE-2024-37085MEDIUMbajo ataqueransomware12 ago 2024
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RIESGO
abrir
anteriorpágina 358 / 2550siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.