Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
13.654 exploits
GitHub PoC1
jesicatjan/WordPress-NotificationX-CVE-2024-1698
CVE-2024-1698CRITICAL16 nov 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC2
WordPress WP Time Capsule Plugin Arbitrary File Upload Vulnerability
CVE-2024-8856CRITICAL16 nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir
GitHub PoC
p33d/Palo-Alto-Expedition-Remote-Code-Execution-Exploit-CVE-2024-5910-CVE-2024-9464
CVE-2024-5910CRITICALbajo ataque15 nov 2024
Expedition: Missing Authentication Leads to Admin Account Takeover
100RIESGO
abrir
GitHub PoC
这是安徽大学 “漏洞分析实验”(大三秋冬)期中作业归档。完整文档位于https://testgames.me/2024/11/10/cve-2021-44228/
CVE-2021-44228CRITICALbajo ataqueransomware15 nov 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
这是一个D-Link rce漏洞 检测程序
CVE-2024-10914CRITICAL15 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC12
Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.
CVE-2024-54756CRITICAL15 nov 2024
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to exe
48RIESGO
abrir
GitHub PoC1
CVE-2024-54761 PoC
CVE-2024-54761MEDIUM15 nov 2024
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RIESGO
abrir
GitHub PoC
Fortigate SSL VPN buffer overflow exploit
CVE-2023-27997CRITICALbajo ataqueransomware14 nov 2024
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC
CiscoRV320Dump CVE-2019-1653 - Automatition.
CVE-2019-1653HIGHbajo ataque14 nov 2024
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
GitHub PoC2
Bash script to automate Local File Inclusion (LFI) attacks on aiohttp server version 3.9.1.
CVE-2024-23334MEDIUM14 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC1
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions leads to (RCE)
CVE-2024-52302HIGH14 nov 2024
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
41RIESGO
abrir
GitHub PoC4
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass
CVE-2024-10924CRITICAL14 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC2
working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln
CVE-2021-21425CRITICAL13 nov 2024
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
GitHub PoC
Ivanti Cloud Services Appliance - Path Traversal
CVE-2024-8963CRITICALbajo ataque13 nov 2024
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RIESGO
abrir
GitHub PoC1
Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability
CVE-2024-21534CRITICAL13 nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RIESGO
abrir
GitHub PoC
This script is specifically designed to solve the challenge on PentesterLab for the CVE-2013-0156 exploit
CVE-2013-015613 nov 2024
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir
GitHub PoC
https://nvd.nist.gov/vuln/detail/CVE-2023-4220
CVE-2023-4220HIGH13 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
CVE-2024-10914_Manual testing with burpsuite
CVE-2024-10914CRITICAL13 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC
fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command
CVE-2021-3156HIGHbajo ataque13 nov 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC1
This repository contains an exploit for CVE-2019-16278 in Nostromo Web Server 1.9.6, allowing remote code execution via a directory traversal vulnerability. The script uses pwntools to establish a reverse shell. For educational and authorized testing use only.
CVE-2019-16278CRITICALbajo ataque12 nov 2024
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC1
Python POC for CVE-2024-32640 Mura CMS SQLi
CVE-2024-32640CRITICAL12 nov 2024
MasaCMS SQL Injection vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2022-21661 docker and poc
CVE-2022-21661HIGH12 nov 2024
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC
Attempt at making the CVE-2024-3400 initial exploit (for educational purposes)
CVE-2024-3400CRITICALbajo ataqueransomware12 nov 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC
CVE: 2015-1328 On python test
CVE-2015-132812 nov 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
GitHub PoC
harshtech123/cve-2020-24881
CVE-2020-2488112 nov 2024
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RIESGO
abrir
GitHub PoC
uthrasri/CVE-2018-14881_no_patch
CVE-2018-14881CRITICAL11 nov 2024
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTA
48RIESGO
abrir
GitHub PoC
To test elasticsearch vulnerabillity on newer version of debian
CVE-2015-1427CRITICALbajo ataque10 nov 2024
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
GitHub PoC
In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10
CVE-2021-44228CRITICALbajo ataqueransomware10 nov 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC48
POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS
CVE-2024-10914CRITICAL10 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC
Automatic Translation <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2024-50493CRITICAL10 nov 2024
WordPress Automatic Translation plugin <= 1.0.4 - Arbitrary File Upload vulnerability
48RIESGO
abrir
anteriorpágina 192 / 456siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.