Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
81.859 exploits
GitHub PoC★ 19
Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)
CVE-2024-43425HIGH23 ago 2024
Moodle: remote code execution via calculated question types
78RIESGO
abrir ↗
GitHub PoC★ 2
Windows远程桌面授权服务CVE-2024-38077检测工具
CVE-2024-38077CRITICAL23 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-7928MEDIUM23 ago 2024
FastAdmin lang path traversal
53RIESGO
abrir ↗
Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
CVE-2024-31214CRITICAL23 ago 2024
Traccar's unrestricted file upload vulnerability in device image upload could lead to remote code execution
48RIESGO
abrir ↗
Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
CVE-2024-24809HIGH23 ago 2024
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RIESGO
abrir ↗
GitHub PoC★ 2
CVE-2024-38063 research so you don't have to.
CVE-2024-38063CRITICAL23 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗
Metasploit300
SolarWinds Web Help Desk Backdoor (CVE-2024-28987)
CVE-2024-28987CRITICALbajo ataque22 ago 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 9
CVE-2024-38856 Exploit
CVE-2024-38856HIGHbajo ataque22 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗
GitHub PoC
Research
CVE-2023-41425MEDIUM22 ago 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2019-11447—22 ago 2024
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque22 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-7928MEDIUM22 ago 2024
FastAdmin lang path traversal
53RIESGO
abrir ↗
GitHub PoC
MLflow LFI/RFI Vulnerability -CVE-2023-1177 - Reproduced
CVE-2023-1177CRITICAL21 ago 2024
Path Traversal: '\..\filename' in mlflow/mlflow
75RIESGO
abrir ↗
GitHub PoC
exr viewer
CVE-2023-50245CRITICAL21 ago 2024
OpenEXR-viewer memory overflow vulnerability
48RIESGO
abrir ↗
GitHub PoC★ 3
Proof-of-Concept for CVE-2024-5932 GiveWP PHP Object Injection
CVE-2024-8353CRITICAL21 ago 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2022-3699HIGH21 ago 2024
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque21 ago 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-5932CRITICAL21 ago 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir ↗
GitHub PoC★ 1
CVE-2023-7028 POC && Exploit
CVE-2023-7028CRITICALbajo ataque21 ago 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
GitHub PoC
Unauthenticated Remote Code Execution – Bricks
CVE-2024-25600CRITICAL20 ago 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗
GitHub PoC
CVE-2023-29384 Auto Exploiter on WordPress Job Board and Recruitment Plugin
CVE-2023-29384CRITICAL20 ago 2024
WordPress WordPress Job Board and Recruitment Plugin – JobWP Plugin <= 2.0 is vulnerable to Arbitrary File Upload
48RIESGO
abrir ↗
GitHub PoC★ 25
PHP CGI Argument Injection (CVE-2024-4577) RCE
CVE-2024-4577CRITICALbajo ataqueransomware20 ago 2024
Argument Injection in PHP-CGI
100RIESGO
abrir ↗
GitHub PoC
RedTeam-Rediron/CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque20 ago 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗
GitHub PoC
A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary workaround. This repository helps secure systems against potential remote code execution risks associated with affected OpenSSH versions.
CVE-2024-6387HIGH20 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗
GitHub PoC
A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the registry to reduce the risk of exploitation without needing the immediate installation of the official Microsoft KB update. Intended as a temporary fix
CVE-2024-38063CRITICAL20 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALbajo ataque20 ago 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-7928MEDIUM20 ago 2024
FastAdmin lang path traversal
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL20 ago 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-7928MEDIUM20 ago 2024
FastAdmin lang path traversal
53RIESGO
abrir ↗
GitHub PoC
Reproducing the following CVEs with dockerfile:CVE-2024-33644 CVE-2024-34370 CVE-2024-22120
CVE-2024-33644CRITICAL20 ago 2024
WordPress Customify Site Library plugin <= 0.0.9 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir ↗
← anteriorpágina 431 / 2729siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.