Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
13.689 exploits
GitHub PoC
PoC CVE-2011-2523
CVE-2011-252327 may 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC8
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
CVE-2024-5084CRITICAL27 may 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RIESGO
abrir
GitHub PoC
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
CVE-2017-548727 may 2024
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
GitHub PoC1
thinhap/CVE-2024-4956-PoC
CVE-2024-4956HIGH27 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC
CVE-2019-10092: Limited Cross-Site Scripting via "Proxy Error" Page in Apache HTTP Server
CVE-2019-1009227 may 2024
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RIESGO
abrir
GitHub PoC
Apache Tomcat - Open Redirect
CVE-2018-1178427 may 2024
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a r
60RIESGO
abrir
GitHub PoC1
TeamCity CVE-2023-42793 exploit written in Rust
CVE-2023-42793CRITICALbajo ataqueransomware27 may 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC
Un exploit con el que puedes aprovecharte de la vulnerabilidad (CVE-2024-23897)
CVE-2024-23897CRITICALbajo ataqueransomware26 may 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC1
changedetection rce though ssti
CVE-2024-32651CRITICAL26 may 2024
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RIESGO
abrir
GitHub PoC2
CVE-2024-4443 Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter
CVE-2024-4443CRITICAL26 may 2024
Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter
68RIESGO
abrir
GitHub PoC1
Joomla! Core SQL Injection
CVE-2015-729726 may 2024
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
GitHub PoC
sn130hk/CVE-2023-44487
CVE-2023-44487HIGHbajo ataque26 may 2024
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC17
[CVE-2024-4956] Nexus Repository Manager 3 Unauthenticated Path Traversal Bulk Scanner
CVE-2024-4956HIGH26 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC28
CVE-2025-8088-BUILDER
CVE-2025-8088HIGHbajo ataque26 may 2024
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
A submodule to demonstrate CVE-2024-32002. Demonstrates arbitrary write into .git.
CVE-2024-32002CRITICAL25 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
Wordpress - Copymatic – AI Content Writer & Generator <= 1.6 - Unauthenticated Arbitrary File Upload
CVE-2024-31351CRITICAL25 may 2024
WordPress Copymatic plugin <= 1.6 - Unauthenticated Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC1
Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion
CVE-2020-3452HIGHbajo ataque25 may 2024
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC
A POC for CVE-2024-32002 demonstrating arbitrary write into the .git directory.
CVE-2024-32002CRITICAL25 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
WordPress Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
CVE-2024-5084CRITICAL25 may 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RIESGO
abrir
GitHub PoC
part of poc cve-2024-32002
CVE-2024-32002CRITICAL24 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC2
Unauthenticated Path Traversal in Nexus Repository 3
CVE-2024-4956HIGH24 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC
PoC Exploit for CVE-2024-32002
CVE-2024-32002CRITICAL23 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC2
10cks/CVE-2024-32002-EXP
CVE-2024-32002CRITICAL23 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
poc of git rce using cve-2024-32002
CVE-2024-32002CRITICAL23 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC3
CVE-2024-4956 Nuclei Template
CVE-2024-4956HIGH23 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC3
Unauthenticated Path Traversal in Nexus Repository 3
CVE-2024-4956HIGH23 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC
PoC Exploit for CVE-2024-32002
CVE-2024-32002CRITICAL23 may 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC1
Nexus Repository Manager 3 Unauthenticated Path Traversal
CVE-2024-4956HIGH23 may 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC1
CVE-2024-4367 mitigation for Odoo 14.0
CVE-2024-4367MEDIUM23 may 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC4
POC for ImageMagick 6.9.6-4. This is a POC which was inspired by fullwaywang discovery of CVE-2023-34152.
CVE-2023-34152CRITICAL23 may 2024
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob wit
48RIESGO
abrir
anteriorpágina 224 / 457siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.