Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
81.859 exploits
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware26 ago 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗
GitHub PoC★ 2
Apache-HTTP-Server-2.4.50-RCE This tool is designed to test Apache servers for the CVE-2021-41773 / CVE-2021-42013 vulnerability. It is intended for educational purposes only and should be used responsibly on systems you have explicit permission to test.
CVE-2021-41773HIGHbajo ataqueransomware26 ago 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
GitHub PoC
RCE OpenSSH CVE-2024-6387 Check and Exploit
CVE-2024-6387HIGH26 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware26 ago 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware26 ago 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
GitHub PoC
sanan2004/CVE-2023-20198
CVE-2023-20198CRITICALbajo ataque26 ago 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗
GitHub PoC
CVE-2024-45265
CVE-2024-45265CRITICAL26 ago 2024
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to exe
48RIESGO
abrir ↗
GitHub PoC
Sudo Privilege Escalation: CVE-2023-22809 Simulation This project simulates the Sudo privilege escalation vulnerability (CVE-2023-22809) to demonstrate how unauthorized root access can be gained. It involves identifying and exploiting this vulnerability in a controlled environment using Parrot OS, the Sudo command, and Bash scripting.
CVE-2023-22809HIGH26 ago 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-5932CRITICAL25 ago 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-21768HIGH25 ago 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALbajo ataque25 ago 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir ↗
GitHub PoC★ 1
Kernel exploit for Xbox SystemOS using CVE-2024-30088
CVE-2024-30088HIGHbajo ataqueransomware25 ago 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir ↗
GitHub PoC★ 2
Modified for GLPI Offsec Lab: call_user_func, array_map, passthru
CVE-2022-35914CRITICALbajo ataque25 ago 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir ↗
GitHub PoC★ 5
LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000
CVE-2024-28000CRITICAL25 ago 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗
GitHub PoC★ 77
GiveWP PHP Object Injection exploit
CVE-2024-5932CRITICAL25 ago 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir ↗
Metasploit600
GiveWP Unauthenticated Donation Process Exploit
CVE-2024-5932CRITICAL25 ago 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir ↗
Metasploit600
GiveWP Unauthenticated Donation Process Exploit
CVE-2024-8353CRITICAL25 ago 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RIESGO
abrir ↗
GitHub PoC★ 3
Telerik Report Server deserialization and authentication bypass exploit chain for CVE-2024-4358/CVE-2024-1800
CVE-2024-4358CRITICALbajo ataque24 ago 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 23
LiteSpeed Cache Privilege Escalation PoC
CVE-2024-28000CRITICAL24 ago 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗
GitHub PoC★ 695
poc for CVE-2024-38063 (RCE in tcpip.sys)
CVE-2024-38063CRITICAL24 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4358CRITICALbajo ataque24 ago 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 3
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
CVE-2024-28995HIGHbajo ataque24 ago 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir ↗
GitHub PoC
TeamCity CVE-2023-42793 RCE (Remote Code Execution)
CVE-2023-42793CRITICALbajo ataqueransomware24 ago 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL24 ago 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir ↗
GitHub PoC
CVE-2023-4220 PoC Chamilo RCE
CVE-2023-4220HIGH24 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-4220HIGH24 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗
GitHub PoC★ 2
Python exploit for Chamilo Unrestricted File Upload Vuln - CVE-2023-4220
CVE-2023-4220HIGH24 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-4220HIGH24 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-28995HIGHbajo ataque24 ago 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware24 ago 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗
← anteriorpágina 430 / 2729siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.