Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
13.654 exploits
GitHub PoC5
CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account
CVE-2024-28000CRITICAL10 sep 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir
GitHub PoC
carradolly/CVE-2015-8660
CVE-2015-866010 sep 2024
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir
GitHub PoC1
CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
CVE-2024-38063CRITICAL10 sep 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC1
Artemisxxx37/OverlayFS-PrivEsc-CVE-2022-0944
CVE-2022-0944CRITICAL10 sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir
GitHub PoC1
KaoXx/CVE-2022-37706
CVE-2022-37706HIGH10 sep 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC3
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
CVE-2024-6624CRITICAL10 sep 2024
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RIESGO
abrir
GitHub PoC9
0xRoqeeb/sqlpad-rce-exploit-CVE-2022-0944
CVE-2022-0944CRITICAL10 sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir
GitHub PoC
PoC code written for CVE-2022-0944 to make exploitation easier. Based on information found here: https://huntr.com/bounties/46630727-d923-4444-a421-537ecd63e7fb
CVE-2022-0944CRITICAL09 sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir
GitHub PoC5
SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944])
CVE-2022-0944CRITICAL09 sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir
GitHub PoC1
CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp
CVE-2024-28000CRITICAL09 sep 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir
GitHub PoC4
CVE-2018-0834 full code exec
CVE-2018-083409 sep 2024
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RIESGO
abrir
GitHub PoC
LucasOneZ/CVE-2023-4966
CVE-2023-4966CRITICALbajo ataqueransomware09 sep 2024
Unauthenticated sensitive information disclosure
100RIESGO
abrir
GitHub PoC
CVE-2024-23897 분석
CVE-2024-23897CRITICALbajo ataqueransomware09 sep 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC4
A proof of concept of the LFI vulnerability on aiohttp 3.9.1
CVE-2024-23334MEDIUM08 sep 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC7
A proof of concept exploit for SQLPad RCE (CVE-2022-0944).
CVE-2022-0944CRITICAL08 sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir
GitHub PoC
quick powershell script to fix cve-2024-38063
CVE-2024-38063CRITICAL07 sep 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC5
🔥 CVE-2024-44849 Exploit
CVE-2024-44849CRITICAL07 sep 2024
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
75RIESGO
abrir
GitHub PoC2
XSS to RCE in RenderTune v1.1.4 exploit
CVE-2024-25292CRITICAL06 sep 2024
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML
48RIESGO
abrir
GitHub PoC
LiteSpeed Unauthorized Account Takeover
CVE-2024-44000CRITICAL06 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
GitHub PoC
test POC for CVE-2019-10149
CVE-2019-10149CRITICALbajo ataque06 sep 2024
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC16
CVE-2024-44000 is a vulnerability in the LiteSpeed Cache plugin, a popular WordPress plugin. This vulnerability affects session management in LiteSpeed Cache, allowing attackers to gain unauthorized access to sensitive data.
CVE-2024-44000CRITICAL06 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
GitHub PoC
deskfiler 1.2.3 Open Redirect exploit
CVE-2024-25291CRITICAL06 sep 2024
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
48RIESGO
abrir
GitHub PoC16
SPIP BigUp Plugin Unauthenticated RCE
CVE-2024-8517CRITICAL06 sep 2024
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir
GitHub PoC
nteract 0.28.0 open redirect to RCE exploit
CVE-2024-22891CRITICAL06 sep 2024
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
48RIESGO
abrir
GitHub PoC12
Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)
CVE-2024-28987CRITICALbajo ataque05 sep 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
GitHub PoC6
fru1ts/CVE-2024-44902
CVE-2024-44902CRITICAL05 sep 2024
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RIESGO
abrir
GitHub PoC
bryanqb07/CVE-2023-32315
CVE-2023-32315HIGHbajo ataque05 sep 2024
Openfire administration console authentication bypass
100RIESGO
abrir
GitHub PoC5
Research and PoC for CVE-2024-6386
CVE-2024-6386CRITICAL05 sep 2024
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
53RIESGO
abrir
GitHub PoC4
Masamuneee/CVE-2024-4367-Analysis
CVE-2024-4367MEDIUM04 sep 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC1
This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.
CVE-2017-5638CRITICALbajo ataqueransomware04 sep 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
anteriorpágina 201 / 456siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.