Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
GitHub PoC
POC for CVE-2023-44487
CVE-2023-44487HIGHbajo ataque19 feb 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir ↗
GitHub PoC★ 1
PAN-OS CVE POC SCRIPT
CVE-2025-0108HIGHbajo ataque19 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir ↗
GitHub PoC
barcrange/CVE-2025-0108-Authentication-Bypass-checker
CVE-2025-0108HIGHbajo ataque19 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir ↗
GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
CVE-2024-34716CRITICAL19 feb 2025
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RIESGO
abrir ↗
GitHub PoC
Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523
CVE-2011-2523—19 feb 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗
GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
CVE-2023-47268MEDIUM19 feb 2025
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RIESGO
abrir ↗
GitHub PoC★ 1
Exploitation Script for CVE-2021-3560
CVE-2021-3560HIGHbajo ataque18 feb 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-4911HIGHbajo ataque18 feb 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque18 feb 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗
GitHub PoC★ 13
Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others
CVE-2024-13159CRITICALbajo ataque18 feb 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir ↗
GitHub PoC
CVE-2023-4911-Looney-Tunables
CVE-2023-4911HIGHbajo ataque18 feb 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-0108HIGHbajo ataque18 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-13159CRITICALbajo ataque18 feb 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir ↗
GitHub PoC★ 2
Detects an authentication bypass vulnerability in Palo Alto PAN-OS (CVE-2025-0108).
CVE-2025-0108HIGHbajo ataque18 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque17 feb 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL17 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗
GitHub PoC
This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to detect exploitation attempts in log data.
CVE-2021-44228CRITICALbajo ataqueransomware17 feb 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
GitHub PoC
sariamubeen/CVE-2024-10924
CVE-2024-10924CRITICAL17 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗
GitHub PoC★ 1
skrkcb2/CVE-2025-0851
CVE-2025-0851CRITICAL17 feb 2025
Path traversal issue in Deep Java Library
53RIESGO
abrir ↗
GitHub PoC★ 1
This Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.
CVE-2024-4367MEDIUM17 feb 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir ↗
GitHub PoC★ 3
sariamubeen/CVE-2023-7028
CVE-2023-7028CRITICALbajo ataque17 feb 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC★ 43
CVE-2025-24016: Wazuh Unsafe Deserialization Remote Code Execution (RCE)
CVE-2025-24016CRITICALbajo ataque16 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir ↗
GitHub PoC
This repository contains a Python script to exploit two vulnerabilities: CVE-2019-18818 and CVE-2019-19609.
CVE-2019-18818—16 feb 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-18818—16 feb 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2025-24016CRITICALbajo ataque16 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir ↗
GitHub PoC
ModeBrutal/CVE-2024-5084-Auto-Exploit
CVE-2024-5084CRITICAL16 feb 2025
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RIESGO
abrir ↗
GitHub PoC
Explore CVE-2023-33580 (XSS) & CVE-2023-33584 (SQLI) discovered by me. Dive into vulnerabilities and exploits for insights.
CVE-2023-33580—16 feb 2025
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RIESGO
abrir ↗
GitHub PoC★ 9
Proof of concept for CVE-2024-42327: Zabbix privilege escalation to RCE
CVE-2024-42327CRITICAL16 feb 2025
SQL injection in user.get API
70RIESGO
abrir ↗
GitHub PoC★ 1
Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567
CVE-2019-0567—15 feb 2025
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir ↗
GitHub PoC
hopsypopsy8/CVE-2020-1938-Exploitation
CVE-2020-1938CRITICALbajo ataque15 feb 2025
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗
← anteriorpágina 379 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.