Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.252exploits catalogados
38.481CVEs con explotación pública
24.695probados en laboratorio
82.081 exploits
VulnCheck XDB
local
CVE-2023-21768HIGH07 abr 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware06 abr 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗
GitHub PoC
RomainBayle08/CVE-2023-38831
CVE-2023-38831HIGHbajo ataqueransomware06 abr 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗
GitHub PoC
Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)
CVE-2024-3094CRITICAL06 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 6
An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.
CVE-2024-3094CRITICAL05 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
DirtyCOW 笔记
CVE-2016-5195HIGHbajo ataque05 abr 2024
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-6634HIGH05 abr 2024
LearnPress <= 4.2.5.7 - Command Injection
56RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-0386HIGHbajo ataque05 abr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware05 abr 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque05 abr 2024
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗
GitHub PoC
churamanib/CVE-2023-0386
CVE-2023-0386HIGHbajo ataque05 abr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗
GitHub PoC★ 1
A small repo with a single playbook.
CVE-2024-3094CRITICAL04 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
Scans liblzma from xu-utils for backdoor (CVE-2024-3094)
CVE-2024-3094CRITICAL04 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 3
A tutorial on how to detect the CVE 2024-3094
CVE-2024-3094CRITICAL04 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 4
Ansible playbooks designed to check and remediate CVE-2024-3094 (XZ Backdoor)
CVE-2024-3094CRITICAL04 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 2
Verify if your installed version of xz-utils is vulnerable to CVE-2024-3094 backdoor
CVE-2024-3094CRITICAL03 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
This is a container environment running CVE-2024-3094 sshd backdoor instance, working with https://github.com/amlweems/xzbot project. IT IS NOT Docker, just implemented by chroot.
CVE-2024-3094CRITICAL03 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 1
The CVE-2024-3094 Checker is a Bash tool for identifying if Linux systems are at risk from the CVE-2024-3094 flaw in XZ/LZMA utilities. It checks XZ versions, SSHD's LZMA linkage, and scans for specific byte patterns, delivering results in a concise table format.
CVE-2024-3094CRITICAL03 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 2
Collection of Detection, Fix, and exploit for CVE-2024-3094
CVE-2024-3094CRITICAL03 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
The repository consists of a checker file that confirms if your xz version and xz-utils package is vulnerable to CVE-2024-3094.
CVE-2024-3094CRITICAL03 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 3
Alicey0719/docker-POC_CVE-2024-1086
CVE-2024-1086HIGHbajo ataqueransomware03 abr 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir ↗
GitHub PoC
LAB: TẤN CÔNG HỆ ĐIỀU HÀNH WINDOWS DỰA VÀO LỖ HỔNG GIAO THỨC SMB.
CVE-2017-0144HIGHbajo ataqueransomware03 abr 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2024-21626HIGH03 abr 2024
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-29269HIGH03 abr 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-1708HIGHbajo ataqueransomware02 abr 2024
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RIESGO
abrir ↗
GitHub PoC
YangHyperData/LOGJ4_PocShell_CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware02 abr 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-1709CRITICALbajo ataqueransomware02 abr 2024
Authentication bypass using an alternate path or channel
100RIESGO
abrir ↗
Exploit-DB
Gibbon LMS v26.0.00 - SSTI vulnerability
CVE-2024-24724CRITICALwebappsphp02 abr 2024
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
53RIESGO
abrir ↗
GitHub PoC★ 1
This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo Application written with Node.js which is containing Remote Code Execution Vulnerability (CVE-2023-32314) for demonstrating all addvantages of this architecture to manage Honeypot systems
CVE-2023-32314CRITICAL02 abr 2024
Sandbox Escape
48RIESGO
abrir ↗
GitHub PoC★ 1
cjybao/CVE-2024-1709-and-CVE-2024-1708
CVE-2024-1709CRITICALbajo ataqueransomware02 abr 2024
Authentication bypass using an alternate path or channel
100RIESGO
abrir ↗
← anteriorpágina 481 / 2737siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.