Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
13.689 exploits
GitHub PoC1
0XFFFF-XD/CVE-2024-4577-PHP-CGI-RCE
CVE-2024-4577CRITICALbajo ataqueransomware12 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC4
jakabakos/CVE-2024-27348-Apache-HugeGraph-RCE
CVE-2024-27348CRITICALbajo ataque12 jun 2024
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
GitHub PoC2
POC for CVE-2024-4577 with Shodan integration
CVE-2024-4577CRITICALbajo ataqueransomware12 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
raytran54/CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware12 jun 2024
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection
CVE-2024-3922CRITICAL12 jun 2024
Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection
75RIESGO
abrir
GitHub PoC5
CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware12 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC25
Ivanti EPM SQL Injection Remote Code Execution Vulnerability
CVE-2024-29824CRITICALbajo ataque12 jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RIESGO
abrir
GitHub PoC
Rejetto http File Server 2.3.x (Reverse shell)
CVE-2014-6287CRITICALbajo ataque12 jun 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC
Basic POC to test CVE-2024-3094 vulnerability inside K8s cluster
CVE-2024-3094CRITICAL11 jun 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
CVE-2022-36446 POC 실습
CVE-2022-3644611 jun 2024
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RIESGO
abrir
GitHub PoC
PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC
CVE-2024-4577CRITICALbajo ataqueransomware11 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
This is a PoC for PHP CVE-2024-4577.
CVE-2024-4577CRITICALbajo ataqueransomware11 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC1
SalehLardhi/CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware11 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC4
NanoWraith/CVE-2024-23692
CVE-2024-23692CRITICALbajo ataque11 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
GitHub PoC29
CVE-2024-37051 poc and exploit
CVE-2024-37051CRITICAL11 jun 2024
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ
48RIESGO
abrir
GitHub PoC90
Veeam Backup Enterprise Manager Authentication Bypass (CVE-2024-29849)
CVE-2024-29849CRITICAL10 jun 2024
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
53RIESGO
abrir
GitHub PoC1
Vulnerability check script for CVE-2024-37393 (SecurEnvoy MFA 9.4.513)
CVE-2024-37393CRITICAL10 jun 2024
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-suppl
63RIESGO
abrir
GitHub PoC
paradox0909/cve-2022-30333_online_rar_extracor
CVE-2022-30333HIGHbajo ataqueransomware10 jun 2024
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RIESGO
abrir
GitHub PoC
feely666/CVE-2024-1086
CVE-2024-1086HIGHbajo ataqueransomware10 jun 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC35
PHP CGI Argument Injection vulnerability
CVE-2024-4577CRITICALbajo ataqueransomware09 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC3
Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.
CVE-2021-44228CRITICALbajo ataqueransomware09 jun 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC9
POC - CVE-2024–24919 - Check Point Security Gateways
CVE-2024-24919HIGHbajo ataqueransomware09 jun 2024
Information disclosure
100RIESGO
abrir
GitHub PoC16
POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal
CVE-2024-4956HIGH09 jun 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC3
itzheartzz/MASS-CVE-2024-27956
CVE-2024-27956CRITICAL09 jun 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC
J4F9S5D2Q7/CVE-2023-43208-MIRTHCONNECT
CVE-2023-43208CRITICALbajo ataqueransomware09 jun 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC
python poc编写练手,可以对单个目标或批量检测
CVE-2024-4577CRITICALbajo ataqueransomware09 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.
CVE-2024-31819CRITICAL09 jun 2024
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath
68RIESGO
abrir
GitHub PoC10
A PoC exploit for CVE-2024-4577 - PHP CGI Argument Injection Remote Code Execution (RCE)
CVE-2024-4577CRITICALbajo ataqueransomware09 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC12
Authentication Bypass Vulnerability — CVE-2024–4358 — Telerik Report Server 2024
CVE-2024-4358CRITICALbajo ataque09 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC5
CVE-2024-4577 nuclei-templates
CVE-2024-4577CRITICALbajo ataqueransomware08 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
anteriorpágina 219 / 457siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.