Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
76.647 exploits
GitHub PoC1
WanLiChangChengWanLiChang/CVE-2024-29972
CVE-2024-29972CRITICAL20 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RIESGO
abrir
GitHub PoC6
This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053).
CVE-2019-905320 jun 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC3
momika233/CVE-2024-29973
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir
GitHub PoC6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
CVE-2023-38831HIGHbajo ataqueransomware19 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC10
POC for CVE-2024-29973
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware19 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir
GitHub PoC
MalekAlthubiany/CVE-2021-43798
CVE-2021-43798HIGHbajo ataque19 jun 2024
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque19 jun 2024
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque19 jun 2024
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir
GitHub PoC6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
CVE-2024-4367MEDIUM19 jun 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC72
CVE-2024-28397: js2py sandbox escape, bypass pyimport restriction.
CVE-2024-28397MEDIUM19 jun 2024
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC
CVE-2022-22947 exploit script
CVE-2022-22947CRITICALbajo ataque19 jun 2024
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
Redfox-Security/Digisol-DG-GR1321-s-Password-Policy-Bypass-CVE-2024-2257
CVE-2024-2257CRITICAL18 jun 2024
Password Policy Bypass Vulnerability in Digisol Router
48RIESGO
abrir
GitHub PoC1
A small tool to create a PoC for CVE-2000-0649.
CVE-2000-064918 jun 2024
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALbajo ataqueransomware18 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware18 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC13
CVE-2024-23692 Exploit
CVE-2024-23692CRITICALbajo ataqueransomware18 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-29824CRITICALbajo ataque18 jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RIESGO
abrir
GitHub PoC
jakabakos/CVE-2024-4577-PHP-CGI-argument-injection-RCE
CVE-2024-4577CRITICALbajo ataqueransomware18 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALbajo ataque18 jun 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
This script is the Proof of Concept (PoC) of the CVE-2024-21413, a significant security vulnerability discovered in the Microsoft Windows Outlook having a strong 9.8 critical CVSS score. Named as #MonikerLink Bug, this vulnerability allows the attacker to execute the arbitrary code remotely on the victim's machine, thus becomes a full-fledged RCE.
CVE-2024-21413CRITICALbajo ataque18 jun 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit500
vCenter Sudo Privilege Escalation
CVE-2024-37081HIGH18 jun 2024
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An auth
36RIESGO
abrir
GitHub PoC1
Ivanti EPM SQL Injection Remote Code Execution Vulnerability(Optimized version based on h3)
CVE-2024-29824CRITICALbajo ataque18 jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RIESGO
abrir
GitHub PoC
Expolit for CVE-2024-23334 (aiohttp >= 1.0.5> && <=3.9.1)
CVE-2024-23334MEDIUM17 jun 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware17 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM17 jun 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALbajo ataqueransomware17 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
GitHub PoC7
CVE-2024-23692
CVE-2024-23692CRITICALbajo ataqueransomware17 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
anteriorpágina 379 / 2555siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.