Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
76.496 exploits
Metasploit500
Asterisk AMI Originate Authenticated RCE
CVE-2024-42365HIGH08 ago 2024
Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
36RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware08 ago 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque08 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
GitHub PoC1
An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
CVE-2024-34102CRITICALbajo ataque08 ago 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC1
CVE-2024-41651
CVE-2024-41651CRITICAL08 ago 2024
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func
48RIESGO
abrir
GitHub PoC
This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack. It provides information on the vulnerable code, recommended fixes, and how to extract and decrypt administrative credentials.
CVE-2024-44541CRITICAL07 ago 2024
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action
48RIESGO
abrir
GitHub PoC6
CVE-2024-32113 Apache OFBIZ Batch Scanning
CVE-2024-32113CRITICALbajo ataque07 ago 2024
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
GitHub PoC
VanishedPeople/CVE-2017-7269
CVE-2017-7269CRITICALbajo ataque07 ago 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque07 ago 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALbajo ataque07 ago 2024
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-6782CRITICAL06 ago 2024
Calibre Remote Code Execution
85RIESGO
abrir
GitHub PoC1
Found this on exploit-db, decided to make my own for practice. This exploit will search out the passwd file and print the contents on a vulnerable system.
CVE-2024-40422CRITICAL06 ago 2024
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RIESGO
abrir
GitHub PoC1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
CVE-2023-4596CRITICAL06 ago 2024
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
CVE-2024-6387HIGH06 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC6
Calibre 远程代码执行(CVE-2024-6782)Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
CVE-2024-6782CRITICAL06 ago 2024
Calibre Remote Code Execution
85RIESGO
abrir
GitHub PoC1
This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.
CVE-2023-38831HIGHbajo ataqueransomware06 ago 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
Metasploit300
Ivanti Virtual Traffic Manager Authentication Bypass (CVE-2024-7593)
CVE-2024-7593CRITICALbajo ataque05 ago 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-1609805 ago 2024
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user t
28RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-7339MEDIUM05 ago 2024
TVT DVR TD-2104TS-CL queryDevInfo information disclosure
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque05 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-26229HIGH04 ago 2024
Windows CSC Service Elevation of Privilege Vulnerability
41RIESGO
abrir
Exploit-DB
Devika v1 - Path Traversal via 'snapshot_path'
CVE-2024-40422CRITICALwebappspython04 ago 2024
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RIESGO
abrir
GitHub PoC2
A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4
CVE-2011-252303 ago 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
Abdurahmon3236/CVE-2024-6366
CVE-2024-6366CRITICAL03 ago 2024
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL03 ago 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir
GitHub PoC
Abdurahmon3236/CVE-2024-36539
CVE-2024-36539CRITICAL03 ago 2024
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t
48RIESGO
abrir
GitHub PoC
nastar-id/CVE-2024-32700
CVE-2024-32700CRITICAL03 ago 2024
WordPress Kognetiks Chatbot for WordPress plugin <= 2.0.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH02 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
Abdurahmon3236/CVE-2024-40110
CVE-2024-40110CRITICAL02 ago 2024
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHbajo ataque02 ago 2024
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
anteriorpágina 360 / 2550siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.