Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
81.759 exploits
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALbajo ataque18 sep 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir ↗
GitHub PoC★ 4
CVE-2022-23131 Zabbix Server SAML authentication exploit
CVE-2022-23131CRITICALbajo ataque18 sep 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALbajo ataque18 sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL17 sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir ↗
GitHub PoC★ 2
0xAgun/CVE-2024-2876
CVE-2024-2876CRITICAL17 sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir ↗
GitHub PoC★ 2
The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads
CVE-2024-43160CRITICAL17 sep 2024
WordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability
63RIESGO
abrir ↗
GitHub PoC★ 3
Client Implementation for the WatchGuard SSO Agent Protocol used for Security Research (CVE-2024-6592, CVE-2024-6593, CVE-2024-6594)
CVE-2024-6592CRITICAL17 sep 2024
WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
48RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL16 sep 2024
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir ↗
GitHub PoC
Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!
CVE-2021-3493HIGHbajo ataque16 sep 2024
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir ↗
GitHub PoC★ 1
PoC code for vulnerability in webmod v0.48. Originally written in 2007, assigned CVE-2007-1260.
CVE-2007-1260—16 sep 2024
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2016-10924—16 sep 2024
The ebook-download plugin before 1.2 for WordPress has directory traversal.
43RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-7965HIGHbajo ataque16 sep 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RIESGO
abrir ↗
GitHub PoC★ 4
Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption
CVE-2023-21716CRITICAL16 sep 2024
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2024-8190HIGHbajo ataque16 sep 2024
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-44000CRITICAL16 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗
GitHub PoC★ 49
This repository contains PoC for CVE-2024-7965. This is the vulnerability in the V8 that occurs only within ARM64.
CVE-2024-7965HIGHbajo ataque16 sep 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RIESGO
abrir ↗
GitHub PoC★ 16
CVE-2024-8190: Ivanti Cloud Service Appliance Command Injection
CVE-2024-8190HIGHbajo ataque16 sep 2024
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RIESGO
abrir ↗
GitHub PoC★ 4
Server-Side Template Injection Exploit
CVE-2024-32651CRITICAL16 sep 2024
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RIESGO
abrir ↗
GitHub PoC★ 3
CVE-2024-44000-LiteSpeed-Cache
CVE-2024-44000CRITICAL16 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALbajo ataqueransomware15 sep 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-1071CRITICAL15 sep 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL15 sep 2024
Code Injection in pyload/pyload
85RIESGO
abrir ↗
GitHub PoC★ 2
dogucyber/WordPress-Exploit-CVE-2024-1071
CVE-2024-1071CRITICAL15 sep 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗
GitHub PoC★ 5
A Bash script for Kali Linux that exploits an iOS WebKit vulnerability (CVE-2020-27950) using Metasploit and ngrok. Automates payload delivery with a public URL via ngrok, checks for required tools, handles errors, and provides an easy way to crash browsers for educational purposes only.
CVE-2020-27950MEDIUMbajo ataque15 sep 2024
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2020-27950MEDIUMbajo ataque15 sep 2024
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-27564MEDIUM15 sep 2024
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RIESGO
abrir ↗
GitHub PoC
New exploit for pyLoad v0.5.0 - Unauthenticated remote code excecution
CVE-2023-0297CRITICAL15 sep 2024
Code Injection in pyload/pyload
85RIESGO
abrir ↗
GitHub PoC★ 49
POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
CVE-2024-23692CRITICALbajo ataqueransomware15 sep 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir ↗
GitHub PoC★ 54
Pre-Auth Exploit for CVE-2024-40711
CVE-2024-40711CRITICALbajo ataqueransomware15 sep 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-6782CRITICAL15 sep 2024
Calibre Remote Code Execution
85RIESGO
abrir ↗
← anteriorpágina 422 / 2726siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.