Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.239exploits catalogados
38.477CVEs con explotación pública
24.695probados en laboratorio
82.004 exploits
GitHub PoC★ 9
local poc for CVE-2024-32002
CVE-2024-32002CRITICAL18 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
GitHub PoC★ 109
CVE-2024-32002 RCE PoC
CVE-2024-32002CRITICAL18 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
GitHub PoC★ 7
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
CVE-2024-21338HIGHbajo ataqueransomware18 may 2024
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir ↗
GitHub PoC★ 4
A PoC exploit for CVE-2014-6271 - Shellshock
CVE-2014-6271CRITICALbajo ataque18 may 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗
GitHub PoC
jakob-pennington/cve-2024-32002-submodule-rce
CVE-2024-32002CRITICAL18 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
GitHub PoC★ 1
jakob-pennington/cve-2024-32002-poc-rce
CVE-2024-32002CRITICAL18 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
GitHub PoC
CVE-2023-4596 Vulnerable Exploit and Checker Version
CVE-2023-4596CRITICAL18 may 2024
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2015-1397—18 may 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque18 may 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-4596CRITICAL18 may 2024
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗
GitHub PoC★ 1
WHOISshuvam/CVE-2015-1397
CVE-2015-1397—18 may 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2024-27972CRITICAL18 may 2024
WordPress WP Fusion Lite plugin <= 3.41.24 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL17 may 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27130HIGH17 may 2024
QTS, QuTS hero
53RIESGO
abrir ↗
GitHub PoC
CVE-2019-9054 exploit added support for python3 + bug fixes
CVE-2019-9053—17 may 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗
GitHub PoC★ 9
(CVE-2024-33559) The XStore theme for WordPress is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query
CVE-2024-33559CRITICAL17 may 2024
WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
48RIESGO
abrir ↗
GitHub PoC★ 18
Hook for the PoC for exploiting CVE-2024-32002
CVE-2024-32002CRITICAL17 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
GitHub PoC★ 1
0xYumeko/CVE-2024-32640-SQLI-MuraCMS
CVE-2024-32640CRITICAL17 may 2024
MasaCMS SQL Injection vulnerability
85RIESGO
abrir ↗
GitHub PoC★ 532
Exploit PoC for CVE-2024-32002
CVE-2024-32002CRITICAL17 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
GitHub PoC
A submodule for exploiting CVE-2024-32002 vulnerability.
CVE-2024-32002CRITICAL17 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
GitHub PoC★ 5
CVE-2024-29895 | RCE on CACTI 1.3.X dev
CVE-2024-29895CRITICAL17 may 2024
Cacti command injection in cmd_realtime.php
85RIESGO
abrir ↗
GitHub PoC★ 2
A proof of concept for the git vulnerability CVE-2024-32002
CVE-2024-32002CRITICAL17 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
GitHub PoC
svchostmm/CVE-2024-25600-mass
CVE-2024-25600CRITICAL17 may 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-29895CRITICAL17 may 2024
Cacti command injection in cmd_realtime.php
85RIESGO
abrir ↗
GitHub PoC
10cks/CVE-2024-21111-del
CVE-2024-21111HIGH17 may 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-32640CRITICAL17 may 2024
MasaCMS SQL Injection vulnerability
85RIESGO
abrir ↗
GitHub PoC★ 27
CVE-2023-34992: Fortinet FortiSIEM Command Injection Proof of Concept Exploit
CVE-2023-34992CRITICAL17 may 2024
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RIESGO
abrir ↗
GitHub PoC★ 14
Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados
CVE-2024-23897CRITICALbajo ataqueransomware16 may 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-29895CRITICAL16 may 2024
Cacti command injection in cmd_realtime.php
85RIESGO
abrir ↗
GitHub PoC
CVE-2016-10033 Wordpress 4.6 Exploit
CVE-2016-10033CRITICALbajo ataque16 may 2024
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗
← anteriorpágina 468 / 2734siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.