Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
13.708 exploits
GitHub PoC72
Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC4
Verify that your XZ Utils version is not vulnerable to CVE-2024-3094
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
OpensourceICTSolutions/xz_utils-CVE-2024-3094
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
Script to detect CVE-2024-3094.
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
Fractal-Tess/CVE-2024-3094
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC8
This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.
CVE-2024-1698CRITICAL29 mar 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2012-0003HIGH28 mar 2024
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RIESGO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2015-1701HIGHbajo ataqueransomware28 mar 2024
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
GitHub PoC
A working POC found while doing a HTB challenge. Original: https://github.com/user0x1337/CVE-2022-39227
CVE-2022-39227CRITICAL28 mar 2024
Python-jwt subject to Authentication Bypass by Spoofing
48RIESGO
abrir
GitHub PoC1
Bludit 3.9.2 Remote Command Execution (RCE)
CVE-2019-1611328 mar 2024
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC
mind2hex/CVE-2022-46169-Cacti-v1.2.22-RCE
CVE-2022-46169CRITICALbajo ataque28 mar 2024
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
Sumitpathania03/Apache-RocketMQ-CVE-2023-33246-
CVE-2023-33246CRITICALbajo ataque28 mar 2024
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2019-0708CRITICALbajo ataqueransomware28 mar 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
Check CVE-2023-42789
CVE-2023-42789CRITICAL28 mar 2024
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0
48RIESGO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2017-0143HIGHbajo ataqueransomware28 mar 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2010-3333HIGHbajo ataque28 mar 2024
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RIESGO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2014-4114HIGHbajo ataque28 mar 2024
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
GitHub PoC
Bludit 3.9.2 auth bruteforce bypass
CVE-2019-17240LOW28 mar 2024
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC5
it's a CVE-2023-28229 (Patched), but feel free to use it for check any outdated software or reseach
CVE-2023-28229HIGHbajo ataque27 mar 2024
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
ticofookfook/CVE-2021-43798
CVE-2021-43798HIGHbajo ataque27 mar 2024
Grafana path traversal
100RIESGO
abrir
GitHub PoC5
Unauthenticated Remote Code Execution (RCE) Vulnerability in WWBNIndex Plugin of AVideo Platform from 12.4 to 14.2
CVE-2024-31819CRITICAL27 mar 2024
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath
68RIESGO
abrir
GitHub PoC1
404fu/CVE-2022-26134-POC
CVE-2022-26134CRITICALbajo ataqueransomware26 mar 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC34
Exploit for CVE-2024-20767 - Adobe ColdFusion
CVE-2024-20767HIGHbajo ataque26 mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC1
Proof of Concept for CVE-2024-20767. Arbitrary file read from Adobe ColdFusion
CVE-2024-20767HIGHbajo ataque26 mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC10
Exploit Toolkit for Adobe ColdFusion CVE-2024-20767 Vulnerability
CVE-2024-20767HIGHbajo ataque26 mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC3
Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using the Log4J vulnerability (CVE-2021-44228). I examined teh amount of endpoints communicating with the server and knowing jnidi as a common in the vulnerbilty found it in clear text
CVE-2021-44228CRITICALbajo ataqueransomware26 mar 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
NMinhTrung/LIFERAY-CVE-2020-7961
CVE-2020-7961CRITICALbajo ataque26 mar 2024
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC
Madan301/CVE-2024-2054
CVE-2024-2054CRITICAL25 mar 2024
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RIESGO
abrir
GitHub PoC9
evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)
CVE-2023-38831HIGHbajo ataqueransomware25 mar 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
CharonDefalt/WordPress--CVE-2022-21661
CVE-2022-21661HIGH24 mar 2024
SQL injection in WordPress
78RIESGO
abrir
anteriorpágina 236 / 457siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.