Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
CVE-2024-28254HIGH15 mar 2024
SpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadata
48RIESGO
abrir
Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
CVE-2024-28255CRITICAL15 mar 2024
Authentication Bypass in OpenMetadata
85RIESGO
abrir
Metasploit600
Ghostscript Command Execution via Format String
CVE-2024-29510MEDIUM14 mar 2024
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with
33RIESGO
abrir
Metasploit600
WordPress wp-automatic Plugin SQLi Admin Creation
CVE-2024-27956CRITICAL13 mar 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
Metasploit300
CVE-2024-20767 - Adobe Coldfusion Arbitrary File Read
CVE-2024-20767HIGHbajo ataque12 mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
Metasploit600
NorthStar C2 XSS to Agent RCE
CVE-2024-28741HIGH12 mar 2024
Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code
58RIESGO
abrir
Metasploit600
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
CVE-2024-2054CRITICAL05 mar 2024
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RIESGO
abrir
Metasploit600
JetBrains TeamCity Unauthenticated Remote Code Execution
CVE-2024-27198CRITICALbajo ataqueransomware04 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
Metasploit600
Judge0 sandbox escape
CVE-2024-28189CRITICAL04 mar 2024
Judge0 vulnerable to Sandbox Escape Patch Bypass via chown running on Symbolic Link
43RIESGO
abrir
Metasploit600
Judge0 sandbox escape
CVE-2024-28185CRITICAL04 mar 2024
Judge0 vulnerable to Sandbox Escape via Symbolic Link
43RIESGO
abrir
Metasploit600
pgAdmin Session Deserialization RCE
CVE-2024-2044CRITICAL04 mar 2024
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
65RIESGO
abrir
Metasploit600
Apache Solr Backup/Restore APIs RCE
CVE-2023-50386HIGH24 feb 2024
Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
58RIESGO
abrir
Metasploit600
ConnectWise ScreenConnect Unauthenticated Remote Code Execution
CVE-2024-1708HIGHbajo ataqueransomware19 feb 2024
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RIESGO
abrir
Metasploit600
Unauthenticated RCE in Bricks Builder Theme
CVE-2024-25600CRITICAL19 feb 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
Metasploit600
ConnectWise ScreenConnect Unauthenticated Remote Code Execution
CVE-2024-1709CRITICALbajo ataqueransomware19 feb 2024
Authentication bypass using an alternate path or channel
100RIESGO
abrir
Metasploit600
QNAP QTS and QuTS Hero Unauthenticated Remote Code Execution in quick.cgi
CVE-2023-47218MEDIUM13 feb 2024
QTS, QuTS hero, QuTScloud
70RIESGO
abrir
Metasploit300
WordPress Ultimate Member SQL Injection (CVE-2024-1071)
CVE-2024-1071CRITICAL10 feb 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
Metasploit300
Rancher Audit Log Sensitive Information Leak
CVE-2023-22649HIGH08 feb 2024
Rancher 'Audit Log' leaks sensitive information
36RIESGO
abrir
Metasploit600
runc (docker) File Descriptor Leak Privilege Escalation
CVE-2024-21626HIGH31 ene 2024
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir
Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
CVE-2024-21887CRITICALbajo ataqueransomware31 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir
Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
CVE-2023-36661HIGH31 ene 2024
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyIn
36RIESGO
abrir
Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
CVE-2024-21893HIGHbajo ataqueransomware31 ene 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RIESGO
abrir
Metasploit300
GitLab Tags RSS feed email disclosure
CVE-2023-5612MEDIUM25 ene 2024
Missing Authorization in GitLab
28RIESGO
abrir
Metasploit300
Jenkins cli Ampersand Replacement Arbitrary File Read
CVE-2024-23897CRITICALbajo ataqueransomware24 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
Metasploit300
Zyxel parse_config.py Command Injection
CVE-2023-33012HIGH24 ene 2024
A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.3
36RIESGO
abrir
Metasploit600
Fortra GoAnywhere MFT Unauthenticated Remote Code Execution
CVE-2024-0204CRITICAL22 ene 2024
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir
Metasploit600
Gambio Online Webshop unauthenticated PHP Deserialization Vulnerability
CVE-2024-23759CRITICAL19 ene 2024
Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" paramete
55RIESGO
abrir
Metasploit600
Atlassian Confluence SSTI Injection
CVE-2023-22527CRITICALbajo ataqueransomware16 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
Metasploit600
Netis router MW5360 unauthenticated RCE.
CVE-2024-22729CRITICAL11 ene 2024
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter
65RIESGO
abrir
Metasploit300
GitLab Password Reset Account Takeover
CVE-2023-7028CRITICALbajo ataque11 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.