Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
CVE-2023-46805HIGHbajo ataqueransomware10 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir
Metasploit300
Wordpress POST SMTP Account Takeover
CVE-2023-6875CRITICAL10 ene 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir
Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
CVE-2024-21887CRITICALbajo ataqueransomware10 ene 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir
Metasploit600
Barracuda ESG Spreadsheet::ParseExcel Arbitrary Code Execution
CVE-2023-7101HIGHbajo ataque24 dic 2023
Arbitrary Code Execution (ACE) Vulnerability
71RIESGO
abrir
Metasploit600
Barracuda ESG Spreadsheet::ParseExcel Arbitrary Code Execution
CVE-2023-710224 dic 2023
Remote Code Execution (RCE) Vulnerability
30RIESGO
abrir
Metasploit600
Cacti RCE via SQLi in pollers.php
CVE-2023-49085HIGH20 dic 2023
Cacti SQL Injection vulnerability
58RIESGO
abrir
Metasploit600
Cacti RCE via SQLi in pollers.php
CVE-2023-49084HIGH20 dic 2023
Local File Inclusion (RCE) in Cacti
48RIESGO
abrir
Metasploit600
MajorDoMo Command Injection
CVE-2023-5091715 dic 2023
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RIESGO
abrir
Metasploit600
WordPress Backup Migration Plugin PHP Filter Chain RCE
CVE-2023-6553CRITICAL11 dic 2023
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir
Metasploit600
GL.iNet Unauthenticated Remote Command Execution via the logread module.
CVE-2023-50445HIGH10 dic 2023
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000
36RIESGO
abrir
Metasploit600
GL.iNet Unauthenticated Remote Command Execution via the logread module.
CVE-2023-50919CRITICAL10 dic 2023
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string
75RIESGO
abrir
Metasploit600
Chamilo v1.11.24 Unrestricted File Upload PHP Webshell
CVE-2023-4220HIGH28 nov 2023
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
Metasploit600
Splunk Authenticated XSLT Upload RCE
CVE-2023-46214HIGH28 nov 2023
Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
58RIESGO
abrir
Metasploit300
Control iD iDSecure Authentication Bypass (CVE-2023-6329)
CVE-2023-6329CRITICAL27 nov 2023
Control iD iDSecure passwordCustom Authentication Bypass
75RIESGO
abrir
Metasploit600
WordPress Royal Elementor Addons RCE
CVE-2023-536023 nov 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
Metasploit300
ownCloud Phpinfo Reader
CVE-2023-49103CRITICALbajo ataque21 nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RIESGO
abrir
Metasploit600
Ray cpu_profile command injection
CVE-2023-6019CRITICAL15 nov 2023
Ray Command Injection in cpu_profile Parameter
85RIESGO
abrir
Metasploit600
Ray Agent Job RCE
CVE-2023-48022CRITICAL15 nov 2023
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RIESGO
abrir
Metasploit300
Ray static arbitrary file read
CVE-2023-6020HIGH15 nov 2023
Ray Static File Local File Include
41RIESGO
abrir
Metasploit600
GitLens Git Local Configuration Exec
CVE-2023-4694414 nov 2023
An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Vis
18RIESGO
abrir
Metasploit300
WordPress WP Fastest Cache Unauthenticated SQLi (CVE-2023-6063)
CVE-2023-606314 nov 2023
WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection
40RIESGO
abrir
Metasploit600
WonderCMS Remote Code Execution
CVE-2023-41425MEDIUM07 nov 2023
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
Metasploit600
Atlassian Confluence Unauth JSON setup-restore Improper Authorization leading to RCE (CVE-2023-22518)
CVE-2023-22518CRITICALbajo ataqueransomware31 oct 2023
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir
Metasploit600
Apache ActiveMQ Unauthenticated Remote Code Execution
CVE-2023-46604CRITICALbajo ataqueransomware27 oct 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
Metasploit600
F5 BIG-IP TMUI AJP Smuggling RCE
CVE-2023-46747CRITICALbajo ataqueransomware26 oct 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir
Metasploit600
Vinchin Backup and Recovery Command Injection
CVE-2023-45498CRITICAL26 oct 2023
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability
68RIESGO
abrir
Metasploit600
Vinchin Backup and Recovery Command Injection
CVE-2023-4549926 oct 2023
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
18RIESGO
abrir
Metasploit300
Citrix ADC (NetScaler) Bleed Scanner
CVE-2023-4966CRITICALbajo ataqueransomware25 oct 2023
Unauthenticated sensitive information disclosure
100RIESGO
abrir
Metasploit600
Mirth Connect Deserialization RCE
CVE-2023-43208CRITICALbajo ataqueransomware25 oct 2023
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
Metasploit600
Mirth Connect Deserialization RCE
CVE-2023-3767925 oct 2023
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary com
40RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.