Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
13.708 exploits
GitHub PoC3
Exploit for Open eClass – CVE-2024-26503: Unrestricted File Upload Leads to Remote Code Execution
CVE-2024-26503CRITICAL15 mar 2024
Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to
48RIESGO
abrir
GitHub PoC
manrop2702/CVE-2020-7961
CVE-2020-7961CRITICALbajo ataque14 mar 2024
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC
A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.
CVE-2023-20048CRITICAL14 mar 2024
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
53RIESGO
abrir
GitHub PoC150
out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability
CVE-2024-21762CRITICALbajo ataqueransomware13 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
GitHub PoC16
Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)
CVE-2024-21762CRITICALbajo ataqueransomware13 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
GitHub PoC
corelight/CVE-2021-38647-noimages
CVE-2021-38647CRITICALbajo ataqueransomware13 mar 2024
Open Management Infrastructure Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
CVE-2023-23752 Data Extractor
CVE-2023-23752MEDIUMbajo ataque12 mar 2024
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC42
Proof-of-concept exploit for CVE-2024-25153.
CVE-2024-25153CRITICAL12 mar 2024
Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
60RIESGO
abrir
GitHub PoC3
hienkiet/CVE-2022-21445-for-12.2.1.3.0-Weblogic
CVE-2022-21445CRITICALbajo ataque12 mar 2024
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
90RIESGO
abrir
GitHub PoC
CSV Injection in Addactis IBNRS 3.10.3.107
CVE-2024-29375CRITICAL11 mar 2024
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a craf
48RIESGO
abrir
GitHub PoC92
Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)
CVE-2024-29059HIGHbajo ataque11 mar 2024
.NET Framework Information Disclosure Vulnerability
100RIESGO
abrir
GitHub PoC17
Demo showing Claude Opus does not find CVE-2023-0266
CVE-2023-0266HIGHbajo ataque10 mar 2024
Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel
71RIESGO
abrir
GitHub PoC8
A PoC exploit for CVE-2024-27198 - JetBrains TeamCity Authentication Bypass
CVE-2024-27198CRITICALbajo ataqueransomware09 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC1
CharonDefalt/CVE-2024-27198-RCE
CVE-2024-27198CRITICALbajo ataqueransomware09 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC3
passwa11/CVE-2024-27198-RCE
CVE-2024-27198CRITICALbajo ataqueransomware08 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
CVE-2019-1722508 mar 2024
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i
23RIESGO
abrir
GitHub PoC
Exploit for CVE-2024-22393 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
CVE-2024-22393CRITICAL08 mar 2024
Apache Answer: Pixel Flood Attack by uploading the large pixel file
48RIESGO
abrir
GitHub PoC2
https://github.com/Phamchie/CVE-2023-3047
CVE-2023-3047CRITICAL08 mar 2024
SQLi in TMT's Lockcell
48RIESGO
abrir
GitHub PoC4
Phamchie/CVE-2023-3047
CVE-2023-3047CRITICAL07 mar 2024
SQLi in TMT's Lockcell
48RIESGO
abrir
GitHub PoC39
hd3s5aa/CVE-2023-21674
CVE-2023-21674HIGHbajo ataque07 mar 2024
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC
A PoC for CVE-2024-27198 written in Go
CVE-2024-27198CRITICALbajo ataqueransomware07 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC3
Brute Hikvision CAMS with CVE-2021-36260 Exploit
CVE-2021-36260CRITICALbajo ataque07 mar 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC17
Progress OpenEdge Authentication Bypass
CVE-2024-1403CRITICAL06 mar 2024
Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
48RIESGO
abrir
GitHub PoC
Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c
CVE-2014-6287CRITICALbajo ataque06 mar 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC4
PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3
CVE-2024-25832HIGH06 mar 2024
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to
46RIESGO
abrir
GitHub PoC157
CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4
CVE-2024-27198CRITICALbajo ataqueransomware06 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC37
Exploit for CVE-2024-27198 - TeamCity Server
CVE-2024-27198CRITICALbajo ataqueransomware05 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC43
ActiveMQ RCE (CVE-2023-46604) 回显利用工具
CVE-2023-46604CRITICALbajo ataqueransomware05 mar 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC
Shubham-2k1/Exploit-CVE-2011-2523
CVE-2011-252305 mar 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC3
CVE-2024-1071 with Docker
CVE-2024-1071CRITICAL04 mar 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
anteriorpágina 238 / 457siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.