Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALbajo ataqueransomware24 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir ↗
GitHub PoC★ 1
Exploit for CVE-2023-4220
CVE-2023-4220HIGH24 ene 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗
GitHub PoC★ 1
CVE-2024-3673 Exploit: Local File Inclusion in Web Directory Free WordPress Plugin ( before 1.7.3 )
CVE-2024-3673CRITICAL24 ene 2025
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RIESGO
abrir ↗
GitHub PoC★ 1
Proof of Concept for CVE-2024-45337 against Gitea and Forgejo
CVE-2024-45337CRITICAL24 ene 2025
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RIESGO
abrir ↗
GitHub PoC★ 8
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
CVE-2024-55591CRITICALbajo ataqueransomware24 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir ↗
GitHub PoC
This repository contains informaion about the Fortigate firewall vulnerability (CVE-2022-40684) and affected data that were publicly disclosed by the Belsen Group. This information is being shared for security research and defensive purposes to help organizations identify if they were impacted.
CVE-2022-40684CRITICALbajo ataqueransomware24 ene 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir ↗
GitHub PoC
CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.
CVE-2017-7921CRITICALbajo ataque24 ene 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALbajo ataque24 ene 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-4220HIGH24 ene 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗
GitHub PoC★ 1
Course Booking System <= 6.0.5 - Unauthenticated SQL Injection
CVE-2025-22785CRITICAL23 ene 2025
WordPress Course Booking System plugin <= 6.0.6 - SQL Injection vulnerability
63RIESGO
abrir ↗
GitHub PoC★ 1
XalfiE/Fortigate-Belsen-Leak-Dump-CVE-2022-40684-
CVE-2022-40684CRITICALbajo ataqueransomware23 ene 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir ↗
GitHub PoC
CVE-2024-38077-POC
CVE-2024-38077CRITICAL23 ene 2025
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-46982HIGH23 ene 2025
Cache Poisoning in next.js
53RIESGO
abrir ↗
GitHub PoC★ 2
ExploitDB CVE-2024-50379 a vulnerability that enables attackers to upload a JSP shell to a vulnerable server and execute commands remotely. The exploit is especially effective when the /uploads directory is either unprotected or missing on the target server.
CVE-2024-50379CRITICAL23 ene 2025
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir ↗
GitHub PoC
Check Point Security Gateways RCE via CVE-2021-40438
CVE-2021-40438CRITICALbajo ataqueransomware22 ene 2025
mod_proxy SSRF
100RIESGO
abrir ↗
GitHub PoC★ 2
Exploit for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways
CVE-2025-0282CRITICALbajo ataqueransomware22 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-40438CRITICALbajo ataqueransomware22 ene 2025
mod_proxy SSRF
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53704HIGHbajo ataqueransomware22 ene 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-0282CRITICALbajo ataqueransomware22 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir ↗
GitHub PoC★ 3
sysirq/fortios-auth-bypass-exploit-CVE-2024-55591
CVE-2024-55591CRITICALbajo ataqueransomware22 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir ↗
GitHub PoC★ 155
This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.
CVE-2025-0411HIGHbajo ataque22 ene 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir ↗
GitHub PoC
备份的CVE
CVE-2024-6460CRITICAL22 ene 2025
Grow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
63RIESGO
abrir ↗
GitHub PoC
Exploit for CVE-2024-53704 - SonicWall SonicOS SSLVPN authentication bypass
CVE-2024-53704HIGHbajo ataqueransomware22 ene 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir ↗
GitHub PoC
In this project, I exploited the CVE-2024-27198-RCE vulnerability to perform a remote code execution (RCE) attack on a vulnerable TeamCity server.
CVE-2024-27198CRITICALbajo ataqueransomware22 ene 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗
GitHub PoC★ 26
sysirq/fortios-auth-bypass-poc-CVE-2024-55591
CVE-2024-55591CRITICALbajo ataqueransomware21 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir ↗
GitHub PoC★ 12
Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE
CVE-2024-41570CRITICAL21 ene 2025
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RIESGO
abrir ↗
GitHub PoC★ 4
themirze/cve-2024-12084
CVE-2024-12084CRITICAL21 ene 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RIESGO
abrir ↗
GitHub PoC★ 8
This is a modified version of the CVE-2024-41570 SSRF PoC from @chebuya chained with the auth RCE exploit from @hyperreality. This exploit executes code remotely to a target due to multiple vulnerabilities in Havoc C2 Framework. (https://github.com/HavocFramework/Havoc)
CVE-2024-41570CRITICAL21 ene 2025
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RIESGO
abrir ↗
GitHub PoC
Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI
CVE-2024-6460CRITICAL21 ene 2025
Grow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
63RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2024-49138HIGHbajo ataque21 ene 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir ↗
← anteriorpágina 385 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.