Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
77.058 exploits
GitHub PoC3
A reproduction of CVE-2019-18634, sudo privilege escalation with buffer overflow.
CVE-2019-1863414 abr 2024
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC
Vulnerabilidad de palo alto
CVE-2024-3400CRITICALbajo ataqueransomware14 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC13
momika233/CVE-2024-3400
CVE-2024-3400CRITICALbajo ataqueransomware14 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC1
Python script for CMS Made Simple 2.1.6 - Remote Code Execution.
CVE-2018-744814 abr 2024
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
28RIESGO
abrir
GitHub PoC2
cve-2020-1938 Tomcat-Ajp-lfi.git脚本
CVE-2020-1938CRITICALbajo ataque14 abr 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC2
Simple CVE-2024-24576 PoC in Julia
CVE-2024-24576CRITICAL14 abr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RIESGO
abrir
GitHub PoC11
Yuvvi01/CVE-2024-3400
CVE-2024-3400CRITICALbajo ataqueransomware13 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC336
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
CVE-2024-21338HIGHbajo ataqueransomware13 abr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC
Demonstration of CVE-2020-11023
CVE-2020-11023MEDIUMbajo ataque13 abr 2024
Potential XSS vulnerability in jQuery
85RIESGO
abrir
GitHub PoC
La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y 5.6.1 de la herramienta de compresión XZ.
CVE-2024-3094CRITICAL13 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
MAL-004: Command Injection Bypass for CVE-2020-12641 in Roundcube Webmail
CVE-2020-12641CRITICALbajo ataque13 abr 2024
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RIESGO
abrir
GitHub PoC2
PoC MinIO vulnerability exploit
CVE-2023-28432HIGHbajo ataque13 abr 2024
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
GitHub PoC
CVE-2024-21413 Setup for CW
CVE-2024-21413CRITICALbajo ataque13 abr 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC72
CVE-2024-3400
CVE-2024-3400CRITICALbajo ataqueransomware13 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC
CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail
CVE-2020-13965MEDIUMbajo ataque13 abr 2024
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML atta
85RIESGO
abrir
GitHub PoC
FoxyProxys/CVE-2024-3400
CVE-2024-3400CRITICALbajo ataqueransomware13 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC2
CerTusHack/CVE-2024-3400-PoC
CVE-2024-3400CRITICALbajo ataqueransomware13 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21338HIGHbajo ataqueransomware13 abr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-28432HIGHbajo ataque13 abr 2024
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-29269HIGH12 abr 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-28255CRITICAL12 abr 2024
Authentication Bypass in OpenMetadata
85RIESGO
abrir
Exploit-DB
MinIO < 2024-01-31T20-20-33Z - Privilege Escalation
CVE-2024-24747HIGHremotego12 abr 2024
MinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
53RIESGO
abrir
Exploit-DB
GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
CVE-2024-31777CRITICALwebappsphp12 abr 2024
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque12 abr 2024
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC5
OpenMetadata_RCE (CVE-2024-28255) Batch scan/exploit
CVE-2024-28255CRITICAL12 abr 2024
Authentication Bypass in OpenMetadata
85RIESGO
abrir
Metasploit600
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
CVE-2024-3400CRITICALbajo ataqueransomware12 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
Metasploit300
Netdata ndsudo privilege escalation
CVE-2024-32019HIGH12 abr 2024
ndsudo: local privilege escalation via untrusted search path
36RIESGO
abrir
Exploit-DB
Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
CVE-2023-6019CRITICALwebappspython12 abr 2024
Ray Command Injection in cpu_profile Parameter
85RIESGO
abrir
GitHub PoC50
CVE-2023-6319 proof of concept
CVE-2023-6319CRITICAL11 abr 2024
Command injection in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service
48RIESGO
abrir
GitHub PoC2
0xWhoami35/CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque11 abr 2024
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
anteriorpágina 408 / 2569siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.