Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.252exploits catalogados
38.481CVEs con explotación pública
24.695probados en laboratorio
82.081 exploits
GitHub PoC
Em fevereiro de 2024, foi identificado duas novas vulnerabilidades que afetam o servidor JetBrains TeamCity (CVE-2024-27198 e CVE-2024-27199)
CVE-2024-27198CRITICALbajo ataqueransomware02 abr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗
GitHub PoC★ 2
Detectar CVE-2024-3094
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 3
apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 14
Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 1
cjybao/CVE-2024-1709-and-CVE-2024-1708
CVE-2024-1709CRITICALbajo ataqueransomware02 abr 2024
Authentication bypass using an alternate path or channel
100RIESGO
abrir ↗
Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
CVE-2024-24497—webappsphp02 abr 2024
20RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-1708HIGHbajo ataqueransomware02 abr 2024
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RIESGO
abrir ↗
GitHub PoC★ 3
CVE-2024-3094 - Checker (fix for arch etc)
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
CVE-2024-3094 XZ Backdoor Detector
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 1
This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo Application written with Node.js which is containing Remote Code Execution Vulnerability (CVE-2023-32314) for demonstrating all addvantages of this architecture to manage Honeypot systems
CVE-2023-32314CRITICAL02 abr 2024
Sandbox Escape
48RIESGO
abrir ↗
Exploit-DB
Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
CVE-2024-24494MEDIUMwebappsphp02 abr 2024
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via t
38RIESGO
abrir ↗
GitHub PoC
YangHyperData/LOGJ4_PocShell_CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware02 abr 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-1709CRITICALbajo ataqueransomware02 abr 2024
Authentication bypass using an alternate path or channel
100RIESGO
abrir ↗
Exploit-DB
Axigen < 10.5.7 - Persistent Cross-Site Scripting
CVE-2023-48974CRITICALwebappsphp02 abr 2024
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware02 abr 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
Exploit-DB
Daily Habit Tracker 1.0 - Broken Access Control
CVE-2024-24496CRITICALwebappsphp02 abr 2024
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,
53RIESGO
abrir ↗
GitHub PoC★ 1
Exploit for CVE-2024-20767 affecting Adobe ColdFusion
CVE-2024-20767HIGHbajo ataque01 abr 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir ↗
GitHub PoC
XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
This is my malware
CVE-2023-38831HIGHbajo ataqueransomware01 abr 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗
GitHub PoC★ 1
Exploit for CVE-2024-20767 affecting Adobe ColdFusion
CVE-2024-20767HIGHbajo ataque01 abr 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-20767HIGHbajo ataque01 abr 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir ↗
GitHub PoC★ 4
Education purpose for CVE-2018-10933
CVE-2018-10933CRITICAL01 abr 2024
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir ↗
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
dah4k/CVE-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 17
XZ Backdoor Extract(Test on Ubuntu 23.10)
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 3
Checker - CVE-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
mightysai1997/CVE-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC★ 1
galacticquest/cve-2024-3094-detect
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
GitHub PoC
mightysai1997/CVE-2024-3094-info
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir ↗
← anteriorpágina 482 / 2737siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.