Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
77.020 exploits
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 may 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC1
Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion
CVE-2020-3452HIGHbajo ataque25 may 2024
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC
Wordpress - Copymatic – AI Content Writer & Generator <= 1.6 - Unauthenticated Arbitrary File Upload
CVE-2024-31351CRITICAL25 may 2024
WordPress Copymatic plugin <= 1.6 - Unauthenticated Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
WordPress Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
CVE-2024-5084CRITICAL25 may 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RIESGO
abrir
GitHub PoC
A submodule to demonstrate CVE-2024-32002. Demonstrates arbitrary write into .git.
CVE-2024-32002CRITICAL25 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
A POC for CVE-2024-32002 demonstrating arbitrary write into the .git directory.
CVE-2024-32002CRITICAL25 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
Metasploit600
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution
CVE-2024-23692CRITICALbajo ataqueransomware25 may 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
GitHub PoC
part of poc cve-2024-32002
CVE-2024-32002CRITICAL24 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
Metasploit300
Ivanti EPM RecordGoodApp SQLi RCE
CVE-2024-29824CRITICALbajo ataque24 may 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RIESGO
abrir
GitHub PoC2
Unauthenticated Path Traversal in Nexus Repository 3
CVE-2024-4956HIGH24 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC8
CVE-2024-3495 Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
CVE-2024-3495CRITICAL23 may 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RIESGO
abrir
GitHub PoC4
POC for ImageMagick 6.9.6-4. This is a POC which was inspired by fullwaywang discovery of CVE-2023-34152.
CVE-2023-34152CRITICAL23 may 2024
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob wit
48RIESGO
abrir
GitHub PoC1
CVE-2024-4367 mitigation for Odoo 14.0
CVE-2024-4367MEDIUM23 may 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
Metasploit600
WordPress Hash Form Plugin RCE
CVE-2024-5084CRITICAL23 may 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-21683HIGH23 may 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-3495CRITICAL23 may 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RIESGO
abrir
GitHub PoC
PoC Exploit for CVE-2024-32002
CVE-2024-32002CRITICAL23 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC3
Unauthenticated Path Traversal in Nexus Repository 3
CVE-2024-4956HIGH23 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC3
CVE-2024-4956 Nuclei Template
CVE-2024-4956HIGH23 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC1
Nexus Repository Manager 3 Unauthenticated Path Traversal
CVE-2024-4956HIGH23 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC2
10cks/CVE-2024-32002-EXP
CVE-2024-32002CRITICAL23 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
PoC Exploit for CVE-2024-32002
CVE-2024-32002CRITICAL23 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
poc of git rce using cve-2024-32002
CVE-2024-32002CRITICAL23 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC2
bfengj/CVE-2024-32002-Exploit
CVE-2024-32002CRITICAL22 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC4
The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based clients and servers using a version of FreeRDP prior to version 3.5.0 or 2.11.6 are vulnerable to out-of-bounds reading12. Versions 3.5.0 and 2.11.6 correct the problem
CVE-2024-32459CRITICAL22 may 2024
FreeRDP Out-Of-Bounds Read in ncrush_decompress
48RIESGO
abrir
GitHub PoC
This is the main repository for CVE 2024-32002, and requires recursive cloning because it contains the submodels necessary for execution.
CVE-2024-32002CRITICAL22 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
CVE-2024-32002-hook
CVE-2024-32002CRITICAL22 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
Repo for testing CVE-2024-32002
CVE-2024-32002CRITICAL22 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
1mxml/CVE-2024-32002-poc
CVE-2024-32002CRITICAL22 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
bfengj/CVE-2024-32002-hook
CVE-2024-32002CRITICAL22 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
anteriorpágina 395 / 2568siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.