Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
76.559 exploits
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware31 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC1
apena-ba/CVE-2024-39304
CVE-2024-39304HIGH31 jul 2024
ChurchCRM SQL Injection Vulnerability
41RIESGO
abrir
GitHub PoC86
GeoServer Remote Code Execution
CVE-2024-36401CRITICALbajo ataque30 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC
Just small script to exploit CVE-2024-32002
CVE-2024-32002CRITICAL30 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
FlojBoj/CVE-2024-32002
CVE-2024-32002CRITICAL30 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
KaSooMi0228/CVE-2024-25600-Bricks-Builder-WordPress
CVE-2024-25600CRITICAL30 jul 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC12
Proof of concept python script for regreSSHion exploit.
CVE-2024-6387HIGH30 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC3
PoC of CVE-2024-32002 - Remote Code Execution while cloning special-crafted local repositories
CVE-2024-32002CRITICAL30 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
12
CVE-2023-25813CRITICAL30 jul 2024
SQL Injection via replacements in sequelize
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque30 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL30 jul 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC80
Windows AppLocker Driver (appid.sys) LPE
CVE-2024-21338HIGHbajo ataqueransomware29 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH29 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC1
CVE-2024-39700 Proof of Concept
CVE-2024-39700CRITICAL29 jul 2024
Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action
48RIESGO
abrir
GitHub PoC
CVE-2023-4220 POC RCE
CVE-2023-4220HIGH29 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
Blind SQL Injection to RCE in a PHP open source application
CVE-2024-40498CRITICAL29 jul 2024
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbit
48RIESGO
abrir
GitHub PoC2
PoC for CVE-2024-34144
CVE-2024-34144CRITICAL29 jul 2024
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_
60RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21338HIGHbajo ataqueransomware29 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC
GIT RCE CVE-2024-32002
CVE-2024-32002CRITICAL29 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
projectforsix/CVE-2021-45428-Defacer
CVE-2021-4542829 jul 2024
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RIESGO
abrir
GitHub PoC
A Reverse shell generator for gitlab-shell vulnerability cve 2024-32002
CVE-2024-32002CRITICAL28 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
CVE-2024-23897 exploit script
CVE-2024-23897CRITICALbajo ataqueransomware28 jul 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC2
veritas-rt/CVE-2010-0219
CVE-2010-021928 jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-5217CRITICALbajo ataque28 jul 2024
Incomplete Input Validation in GlideExpression Script
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2010-021928 jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware28 jul 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC2
vvts-alpha/CVE-2010-0219
CVE-2010-021928 jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALbajo ataque28 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHbajo ataqueransomware28 jul 2024
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
This repository contains scripts and resources for exploiting the Follina CVE and CVE-2021-40444 vulnerabilities in Microsoft Office. The scripts generate malicious document files that can execute arbitrary code on the target system.
CVE-2021-40444HIGHbajo ataqueransomware28 jul 2024
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 363 / 2552siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.