Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
76.647 exploits
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALbajo ataque27 jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALbajo ataque27 jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-27163MEDIUM27 jun 2024
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-49103CRITICALbajo ataque27 jun 2024
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RIESGO
abrir
GitHub PoC
This is a simple proof of concept for CVE-2023-49103.
CVE-2023-49103CRITICALbajo ataque27 jun 2024
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RIESGO
abrir
GitHub PoC95
A Pwn2Own 2024 SpiderMonkey JIT Bug: From Integer Range Inconsistency to Bound Check Elimination then RCE
CVE-2024-29943CRITICAL27 jun 2024
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RIESGO
abrir
GitHub PoC8
🆘New Windows Kernel Priviledge Escalation Vulnerability
CVE-2024-30088HIGHbajo ataqueransomware27 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
Exploit-DB
SolarWinds Platform 2024.1 SR1 - Race Condition
CVE-2024-28999MEDIUMwebappsmultiple26 jun 2024
SolarWinds Platform Race Condition Vulnerability
38RIESGO
abrir
GitHub PoC1
ggfzx/CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware26 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC1
Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions
CVE-2024-28995HIGHbajo ataque26 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-28995HIGHbajo ataque26 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware26 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
zerobytesecure/CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware25 jun 2024
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
CVE-2023-38831HIGHbajo ataqueransomware25 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC1
The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool.
CVE-2019-905325 jun 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
CVE-2024-6028 Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
CVE-2024-6028CRITICAL25 jun 2024
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALbajo ataqueransomware25 jun 2024
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-6028CRITICAL25 jun 2024
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RIESGO
abrir
Metasploit300
Fortra FileCatalyst Workflow SQL Injection (CVE-2024-5276)
CVE-2024-5276CRITICAL25 jun 2024
SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
65RIESGO
abrir
GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
CVE-2021-34527HIGHbajo ataqueransomware25 jun 2024
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit300
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
CVE-2024-5806CRITICAL25 jun 2024
MOVEit Transfer Authentication Bypass Vulnerability
85RIESGO
abrir
GitHub PoC1
This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)
CVE-2024-4577CRITICALbajo ataqueransomware24 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC290
tykawaii98/CVE-2024-30088
CVE-2024-30088HIGHbajo ataqueransomware24 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC45
Exploit for the CVE-2024-5806
CVE-2024-5806CRITICAL24 jun 2024
MOVEit Transfer Authentication Bypass Vulnerability
85RIESGO
abrir
GitHub PoC1
Proof of concept of CVE-2024-29868 affecting Apache StreamPipes from 0.69.0 through 0.93.0
CVE-2024-29868CRITICAL24 jun 2024
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-5806CRITICAL24 jun 2024
MOVEit Transfer Authentication Bypass Vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2018-9995
CVE-2018-999524 jun 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
local
CVE-2024-30088HIGHbajo ataqueransomware24 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-999524 jun 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21338HIGHbajo ataqueransomware23 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
anteriorpágina 377 / 2555siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.