Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.044exploits catalogados
35.296CVEs con explotación pública
24.695probados en laboratorio
77.044 exploits
GitHub PoC11
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793
CVE-2023-42793CRITICALbajo ataqueransomware24 abr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC
Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.
CVE-2024-3400CRITICALbajo ataqueransomware24 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC6
Simple honeypot for CVE-2024-3400 Palo Alto PAN-OS Command Injection Vulnerability
CVE-2024-3400CRITICALbajo ataqueransomware24 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALbajo ataque24 abr 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware24 abr 2024
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
CVE-2019-9670CRITICALbajo ataque24 abr 2024
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware24 abr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC4
PoC exploit for GLPI - Command injection using a third-party library script
CVE-2022-35914CRITICALbajo ataque24 abr 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALbajo ataque23 abr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC
A basic script that exploits CVE-2011-2523
CVE-2011-252323 abr 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-3273HIGHbajo ataque23 abr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21338HIGHbajo ataqueransomware23 abr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
Metasploit600
Flowmon Unauthenticated Command Injection
CVE-2024-2389CRITICAL23 abr 2024
Flowmon Unauthenticated Command Injection Vulnerability
85RIESGO
abrir
GitHub PoC
mrrobot0o/CVE-2024-3273-
CVE-2024-3273HIGHbajo ataque23 abr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir
GitHub PoC1
A final project for "Network Security" class at NYCU (National Yang Ming Chiao Tung University, Taiwan). Exploiting a CVE in "EasyAppointments" software.
CVE-2022-0482CRITICAL22 abr 2024
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RIESGO
abrir
GitHub PoC
CVE-2023-0386 包含所需运行库
CVE-2023-0386HIGHbajo ataque22 abr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
Metasploit600
Apache HugeGraph Gremlin RCE
CVE-2024-27348CRITICALbajo ataque22 abr 2024
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
GitHub PoC
CVE-2022-24716 (Arbitrary File Disclosure Icingaweb2)
CVE-2022-24716HIGH22 abr 2024
Path traversal in Icinga Web 2
78RIESGO
abrir
GitHub PoC36
CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information
CVE-2024-27198CRITICALbajo ataqueransomware22 abr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC216
Oracle VirtualBox Elevation of Privilege (Local Privilege Escalation) Vulnerability
CVE-2024-21111HIGH22 abr 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RIESGO
abrir
GitHub PoC6
A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read
CVE-2018-14847CRITICALbajo ataque22 abr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALbajo ataqueransomware22 abr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHbajo ataque22 abr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-24716HIGH22 abr 2024
Path traversal in Icinga Web 2
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-0482CRITICAL22 abr 2024
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALbajo ataque22 abr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27199HIGHbajo ataqueransomware22 abr 2024
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RIESGO
abrir
GitHub PoC
TYuan0816/cve-2023-44487
CVE-2023-44487HIGHbajo ataque22 abr 2024
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC
SOPlanning 1.52.00 CSRF/SQLi/XSS (CVE-2024-33722, CVE-2024-33724)
CVE-2024-33722MEDIUM22 abr 2024
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
33RIESGO
abrir
GitHub PoC
Python exploit and checker script for CVE-2024-3400 Palo Alto Command Injection and Arbitrary File Creation
CVE-2024-3400CRITICALbajo ataqueransomware21 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
anteriorpágina 404 / 2569siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.