Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
GitHub PoC
Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation
CVE-2024-54369CRITICAL19 dic 2024
WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
48RIESGO
abrir ↗
GitHub PoC★ 1
yiliufeng168/CVE-2024-50379-POC
CVE-2024-50379CRITICAL19 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir ↗
Metasploit600
Craft CMS Twig Template Injection RCE via FTP Templates Path
CVE-2024-56145CRITICALbajo ataque19 dic 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware19 dic 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2009-2265—18 dic 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗
GitHub PoC★ 4
v3153/CVE-2024-50379-POC
CVE-2024-50379CRITICAL18 dic 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗
GitHub PoC
CVE-2023-4966-exploit
CVE-2023-4966CRITICALbajo ataqueransomware18 dic 2024
Unauthenticated sensitive information disclosure
100RIESGO
abrir ↗
GitHub PoC★ 1
Adobe ColdFusion 8 - Remote Command Execution (RCE)
CVE-2009-2265—18 dic 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir ↗
GitHub PoC★ 2
dustblessnotdust/CVE-2024-53677-S2-067-thread
CVE-2024-53677CRITICAL18 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗
GitHub PoC★ 3
yangyanglo/CVE-2024-53677
CVE-2024-53677CRITICAL17 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗
GitHub PoC★ 3
A Docker-based environment to reproduce the CVE-2024-53677 vulnerability in Apache Struts 2.
CVE-2024-53677CRITICAL17 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗
GitHub PoC★ 6
Proof of concept (POC) for CVE-2024-45337
CVE-2024-45337CRITICAL17 dic 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RIESGO
abrir ↗
GitHub PoC★ 1
An example project that showcases golang code vulnerable to CVE-2024-45337
CVE-2024-45337CRITICAL17 dic 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL17 dic 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-12725—16 dic 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗
GitHub PoC
DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection
CVE-2024-50507CRITICAL16 dic 2024
WordPress DS.DownloadList plugin <= 1.3 - PHP Object Injection vulnerability
48RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2024-49039HIGHbajo ataqueransomware16 dic 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2024-1086HIGHbajo ataqueransomware16 dic 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir ↗
GitHub PoC★ 21
LLfam/CVE-2024-1086
CVE-2024-1086HIGHbajo ataqueransomware16 dic 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir ↗
GitHub PoC★ 14
A short scraper looking for a POC of CVE-2024-49112
CVE-2024-49112CRITICAL16 dic 2024
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RIESGO
abrir ↗
GitHub PoC
t0mmy4/CVE-2019-12725-modified-exp
CVE-2019-12725—16 dic 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗
GitHub PoC
Rahul-Thakur7/CVE-2023-21554
CVE-2023-21554CRITICAL16 dic 2024
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RIESGO
abrir ↗
GitHub PoC★ 1
The EXP/POC of CVE-2019-12725
CVE-2019-12725—16 dic 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2024-12356CRITICALbajo ataque16 dic 2024
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
100RIESGO
abrir ↗
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2025-1094HIGH16 dic 2024
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RIESGO
abrir ↗
GitHub PoC
redspy-sec/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware16 dic 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware16 dic 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-12725—16 dic 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗
← anteriorpágina 394 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.