Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
13.689 exploits
GitHub PoC
P3wc0/CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware31 may 2024
Information disclosure
100RIESGO
abrir
GitHub PoC47
seed1337/CVE-2024-24919-POC
CVE-2024-24919HIGHbajo ataqueransomware31 may 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
Vulnpire/CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware31 may 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
DLL Injection and CVE-2010-3124
CVE-2010-312431 may 2024
Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possib
28RIESGO
abrir
GitHub PoC
cve-2024-32002yahhh
CVE-2024-32002CRITICAL31 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
CVE-2024-32002wakuwaku
CVE-2024-32002CRITICAL31 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
quartz with CVE-2019-13990
CVE-2019-13990CRITICAL31 may 2024
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attack
53RIESGO
abrir
GitHub PoC1
El script explota una vulnerabilidad de deserialización insegura en Apache ActiveMQ (CVE-2023-46604)
CVE-2023-46604CRITICALbajo ataqueransomware31 may 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC
CVE-2024-32002 poc test
CVE-2024-32002CRITICAL30 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC7
Nuclei Template to discover CVE-2024-24919. A path traversal vulnerability in CheckPoint SSLVPN.
CVE-2024-24919HIGHbajo ataqueransomware30 may 2024
Information disclosure
100RIESGO
abrir
GitHub PoC3
Quick and simple script that takes as input a file with multiple URLs to check for the CVE-2024-24919 vulnerability in CHECKPOINT
CVE-2024-24919HIGHbajo ataqueransomware30 may 2024
Information disclosure
100RIESGO
abrir
GitHub PoC12
CVE-2024-24919 Exploit PoC
CVE-2024-24919HIGHbajo ataqueransomware30 may 2024
Information disclosure
100RIESGO
abrir
GitHub PoC1
Exploit for CVE-2024-4956 affecting all previous Sonatype Nexus Repository 3.x OSS/Pro versions up to and including 3.68.0
CVE-2024-4956HIGH30 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC
hendprw/CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware30 may 2024
Information disclosure
100RIESGO
abrir
GitHub PoC5
POC exploit for CVE-2024-24919 information leakage
CVE-2024-24919HIGHbajo ataqueransomware30 may 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
am-eid/CVE-2024-24919
CVE-2024-24919HIGHbajo ataqueransomware30 may 2024
Information disclosure
100RIESGO
abrir
GitHub PoC
CVE-2020-5377: Dell OpenManage Server Administrator File Read
CVE-2020-5377CRITICAL29 may 2024
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RIESGO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) PoC Application
CVE-2021-44228CRITICALbajo ataqueransomware29 may 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
confluence rce (CVE-2021-26084, CVE-2022-26134, CVE-2023-22527)
CVE-2021-26084CRITICALbajo ataqueransomware29 may 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC12
Эксплойт для уязвимости CVE-2024-0039 на Android, который позволяет выполнять произвольный код через MP4 файл. Этот репозиторий создан для образовательных целей.
CVE-2024-0039CRITICAL29 may 2024
In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This
48RIESGO
abrir
GitHub PoC
CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.
CVE-2023-46604CRITICALbajo ataqueransomware29 may 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC5
confluence rce (CVE-2021-26084, CVE-2022-26134, CVE-2023-22527)
CVE-2022-26134CRITICALbajo ataqueransomware29 may 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC5
confluence rce (CVE-2021-26084, CVE-2022-26134, CVE-2023-22527)
CVE-2023-22527CRITICALbajo ataqueransomware29 may 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
GitHub PoC1
Goplush/CVE-2024-32002-git-rce
CVE-2024-32002CRITICAL28 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC5
POC iteration for CVE-2024-23108 which can use -l for list input
CVE-2024-23108CRITICAL28 may 2024
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RIESGO
abrir
GitHub PoC1
The Country State City Dropdown CF7 WordPress plugin (versions up to 2.7.2) is vulnerable to SQL Injection via 'cnt' and 'sid' parameters. Insufficient escaping and lack of preparation in the SQL query allow unauthenticated attackers to append queries, potentially extracting sensitive database information.
CVE-2024-3495CRITICAL28 may 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RIESGO
abrir
GitHub PoC1
Microsoft Windows 'HTTP.sys' - Remote Code Execution
CVE-2015-1635CRITICALbajo ataque28 may 2024
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC1
Hoanle396/CVE-2021-44228-demo
CVE-2021-44228CRITICALbajo ataqueransomware28 may 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
CVE-2024-4956 : Nexus Repository Manager 3 poc exploit
CVE-2024-4956HIGH28 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC2
Demo for CVE-2023-43654 - Remote Code Execution in PyTorch TorchServe
CVE-2023-43654CRITICAL28 may 2024
TorchServe Server-Side Request Forgery
75RIESGO
abrir
anteriorpágina 223 / 457siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.