Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
76.647 exploits
GitHub PoC1
Chamilo LMS Unauthenticated Remote Code Execution
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC5
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALbajo ataque07 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
YISF 2024 CTF-Web (Directory Traversal via ".tar" file, CVE-2007-4559), easy
CVE-2007-4559CRITICAL07 jul 2024
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RIESGO
abrir
GitHub PoC
sysonlai/CVE-2024-32002-hook
CVE-2024-32002CRITICAL07 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC1
RCE Chamilo 1.11.24
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque06 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC7
PoC - PHP CGI Argument Injection CVE-2024-4577 (Scanner and Exploit)
CVE-2024-4577CRITICALbajo ataqueransomware06 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RIESGO
abrir
GitHub PoC56
Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit
CVE-2024-36401CRITICALbajo ataque06 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware06 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC2
SSH EXPLOIT BYPASS AUTH SSH
CVE-2024-3094CRITICAL05 jul 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
imv7/CVE-2024-6387
CVE-2024-6387HIGH05 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27532HIGHbajo ataqueransomware05 jul 2024
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RIESGO
abrir
VulnCheck XDB
local
CVE-2024-30088HIGHbajo ataqueransomware05 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware05 jul 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC
puckiestyle/CVE-2023-27532-RCE-Only
CVE-2023-27532HIGHbajo ataqueransomware05 jul 2024
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RIESGO
abrir
GitHub PoC1
TeamCity RCE for Linux (CVE-2023-42793)
CVE-2023-42793CRITICALbajo ataqueransomware05 jul 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC44
该漏洞存在于 NtQueryInformationToken 函数中,特别是在处理AuthzBasepCopyoutInternalSecurityAttributes 函数时,该漏洞源于内核在操作对象时对锁定机制的不当管理,这一失误可能导致恶意实体意外提升权限。
CVE-2024-30088HIGHbajo ataqueransomware05 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC10
HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).
CVE-2024-6387HIGH05 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC4
POC
CVE-2024-36401CRITICALbajo ataque05 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
anteriorpágina 371 / 2555siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.