Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
81.859 exploits
GitHub PoC★ 9
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
CVE-2024-7954CRITICAL01 sep 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir ↗
GitHub PoC★ 25
CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC
CVE-2024-21413CRITICALbajo ataque31 ago 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-21413CRITICALbajo ataque31 ago 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 11
POC for CVE-2023-29360
CVE-2023-29360HIGHbajo ataque31 ago 2024
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RIESGO
abrir ↗
GitHub PoC
🔍 Just wrapped up an incident report on a Phishing Alert (Event ID 257, SOC282). Enhancing my expertise in email threat detection and response! 🚨 #Cybersecurity #SOCAnalyst #LetsDefend
CVE-2024-24919HIGHbajo ataqueransomware31 ago 2024
Information disclosure
100RIESGO
abrir ↗
GitHub PoC
Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0
CVE-2024-44812CRITICAL31 ago 2024
SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the usern
48RIESGO
abrir ↗
GitHub PoC★ 43
CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)
CVE-2024-38063CRITICAL31 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-29360HIGHbajo ataque31 ago 2024
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-7029HIGH30 ago 2024
Command Injection in AVTech AVM1203 (IP Camera)
68RIESGO
abrir ↗
GitHub PoC★ 35
sinsinology/CVE-2024-6670
CVE-2024-6670CRITICALbajo ataqueransomware30 ago 2024
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RIESGO
abrir ↗
GitHub PoC
A POC demo on CVE-2023-38831
CVE-2023-38831HIGHbajo ataqueransomware30 ago 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-7120MEDIUM30 ago 2024
Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection
70RIESGO
abrir ↗
GitHub PoC★ 23
Proof of concept : CVE-2024-1071: WordPress Vulnerability Exploited
CVE-2024-1071CRITICAL30 ago 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗
GitHub PoC★ 140
exploits for CVE-2024-20017
CVE-2024-20017CRITICAL30 ago 2024
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote cod
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-6670CRITICALbajo ataqueransomware30 ago 2024
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-1071CRITICAL30 ago 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware30 ago 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware29 ago 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗
GitHub PoC
LuisMateo1/Arbitrary-File-Read-CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware29 ago 2024
Information disclosure
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware29 ago 2024
Information disclosure
100RIESGO
abrir ↗
GitHub PoC★ 295
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
CVE-2017-12615HIGHbajo ataqueransomware29 ago 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware29 ago 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALbajo ataque29 ago 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗
GitHub PoC★ 83
mistymntncop/CVE-2024-5274
CVE-2024-5274HIGHbajo ataque29 ago 2024
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
71RIESGO
abrir ↗
Metasploit300
WhatsUp Gold SQL Injection (CVE-2024-6670)
CVE-2024-6670CRITICALbajo ataqueransomware29 ago 2024
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-5274HIGHbajo ataque29 ago 2024
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
71RIESGO
abrir ↗
GitHub PoC★ 7
Fully automated PoC - CVE-2024-25641 - RCE - Cacti < v1.2.26 🌵
CVE-2024-25641CRITICAL29 ago 2024
Cacti RCE vulnerability when importing packages
85RIESGO
abrir ↗
GitHub PoC★ 3
CVE-2019-15107 Webmin unauthenticated RCE
CVE-2019-15107CRITICALbajo ataqueransomware29 ago 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗
GitHub PoC★ 295
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
CVE-2020-1938CRITICALbajo ataque29 ago 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗
GitHub PoC★ 1
In an era where digital security is crucial, a new vulnerability in OpenSSH, identified as CVE-2024-6387, has drawn the attention of system administrators and security professionals worldwide. Named "regreSSHion," this severe security flaw allows remote code execution (RCE) and could significant threat to the integrity of vulnerable systems.
CVE-2024-6387HIGH29 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗
← anteriorpágina 428 / 2729siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.