Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
13.708 exploits
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
dah4k/CVE-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC17
XZ Backdoor Extract(Test on Ubuntu 23.10)
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
This is my malware
CVE-2023-38831HIGHbajo ataqueransomware01 abr 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC4
Education purpose for CVE-2018-10933
CVE-2018-10933CRITICAL01 abr 2024
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC1
Exploit for CVE-2024-20767 affecting Adobe ColdFusion
CVE-2024-20767HIGHbajo ataque01 abr 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC
Mustafa1986/CVE-2024-3094
CVE-2024-3094CRITICAL31 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL31 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC45
jfrog/cve-2024-3094-tools
CVE-2024-3094CRITICAL31 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC1
upgraded of BlueBourne CVE-2017-0785 to python3
CVE-2017-078531 mar 2024
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC4
A script to detect if xz is vulnerable - CVE-2024-3094
CVE-2024-3094CRITICAL31 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
spidygal/CVE-2024-3094-Nmap-NSE-script
CVE-2024-3094CRITICAL31 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
Ansible playbook for patching CVE-2024-3094
CVE-2024-3094CRITICAL31 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC1
hapa3/CVE-2024-31666
CVE-2024-31666CRITICAL31 mar 2024
An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon
48RIESGO
abrir
GitHub PoC1
efekaanakkar/CVE-2024-30998
CVE-2024-30998CRITICAL30 mar 2024
SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrar
48RIESGO
abrir
GitHub PoC
More specific : Dirty COW (CVE-2016-5195)
CVE-2016-5195HIGHbajo ataque30 mar 2024
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC11
K8S and Docker Vulnerability Check for CVE-2024-3094
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC5
wgetnz/CVE-2024-3094-check
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC1
Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code.
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC10
History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
ashwani95/CVE-2024-3094
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
hazemkya/CVE-2024-3094-checker
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC26
Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6) or upgrading to latest version. Added Ansible Playbook
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC2
Horizon-Software-Development/CVE-2024-3094
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC147
An ssh honeypot with the XZ backdoor. CVE-2024-3094
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC1
brinhosa/CVE-2024-3094-One-Liner
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC72
Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC6
ShadowRay RCE POC (CVE-2023-48022)
CVE-2023-48022CRITICAL29 mar 2024
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RIESGO
abrir
GitHub PoC8
This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.
CVE-2024-1698CRITICAL29 mar 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir
anteriorpágina 235 / 457siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.