Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
ISPConfig language_edit.php PHP Code Injection
CVE-2023-46818HIGH24 oct 2023
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by
41RIESGO
abrir
Metasploit600
Cisco IOX XE Unauthenticated RCE Chain
CVE-2023-20198CRITICALbajo ataque16 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
Metasploit600
Cisco IOX XE Unauthenticated RCE Chain
CVE-2023-20273HIGHbajo ataque16 oct 2023
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RIESGO
abrir
Metasploit300
Cisco IOX XE unauthenticated OS command execution
CVE-2023-20198CRITICALbajo ataque16 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
Metasploit300
Cisco IOX XE unauthenticated OS command execution
CVE-2023-20273HIGHbajo ataque16 oct 2023
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RIESGO
abrir
Metasploit300
Cisco IOX XE unauthenticated Command Line Interface (CLI) execution
CVE-2023-20198CRITICALbajo ataque16 oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
Metasploit600
Atlassian Confluence Unauthenticated Remote Code Execution
CVE-2023-22515CRITICALbajo ataqueransomware04 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
Metasploit300
Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control
CVE-2023-22515CRITICALbajo ataqueransomware04 oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
Metasploit600
PyTorch Model Server Registration and Deserialization RCE
CVE-2023-43654CRITICAL03 oct 2023
TorchServe Server-Side Request Forgery
75RIESGO
abrir
Metasploit600
PyTorch Model Server Registration and Deserialization RCE
CVE-2022-1471HIGH03 oct 2023
Remote Code execution in SnakeYAML
58RIESGO
abrir
Metasploit600
Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
CVE-2023-4911HIGHbajo ataque03 oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
Metasploit600
Kafka UI Unauthenticated Remote Command Execution via the Groovy Filter option.
CVE-2023-52251HIGH27 sep 2023
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the
78RIESGO
abrir
Metasploit600
Progress Software WS_FTP Unauthenticated Remote Code Execution
CVE-2023-40044CRITICALbajo ataqueransomware27 sep 2023
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RIESGO
abrir
Metasploit600
JetBrains TeamCity Unauthenticated Remote Code Execution
CVE-2023-42793CRITICALbajo ataqueransomware19 sep 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
Metasploit600
Craft CMS unauthenticated Remote Code Execution (RCE)
CVE-2023-41892CRITICAL13 sep 2023
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir
Metasploit600
Themebleed- Windows 11 Themes Arbitrary Code Execution CVE-2023-38146
CVE-2023-38146HIGH13 sep 2023
Windows Themes Remote Code Execution Vulnerability
48RIESGO
abrir
Metasploit400
Apache Superset Signed Cookie RCE
CVE-2023-37941MEDIUM06 sep 2023
Apache Superset: Metadata db write access can lead to remote code execution
53RIESGO
abrir
Metasploit400
Apache Superset Signed Cookie RCE
CVE-2023-27524HIGHbajo ataque06 sep 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
Metasploit400
Apache Superset Signed Cookie RCE
CVE-2023-39265LOW06 sep 2023
Apache Superset: Possible Unauthorized Registration of SQLite Database Connections
45RIESGO
abrir
Metasploit600
VMWare Aria Operations for Networks (vRealize Network Insight) SSH Private Key Exposure
CVE-2023-34039CRITICAL29 ago 2023
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RIESGO
abrir
Metasploit600
LG Simple Editor Remote Code Execution
CVE-2023-40498CRITICAL24 ago 2023
LG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability
65RIESGO
abrir
Metasploit600
WinRAR CVE-2023-38831 Exploit
CVE-2023-38831HIGHbajo ataqueransomware23 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
Metasploit600
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
CVE-2023-38035CRITICALbajo ataqueransomware21 ago 2023
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RIESGO
abrir
Metasploit300
ThinManager Path Traversal (CVE-2023-2917) Arbitrary File Upload
CVE-2023-2917CRITICAL17 ago 2023
Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
65RIESGO
abrir
Metasploit600
Junos OS PHPRC Environment Variable Manipulation RCE
CVE-2023-36845CRITICALbajo ataque17 ago 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
Metasploit300
ThinManager Path Traversal (CVE-2023-2915) Arbitrary File Delete
CVE-2023-2915HIGH17 ago 2023
Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
58RIESGO
abrir
Metasploit600
Ivanti Avalanche MDM Buffer Overflow
CVE-2023-32560HIGH14 ago 2023
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RIESGO
abrir
Metasploit600
PRTG CVE-2023-32781 Authenticated RCE
CVE-2023-3278109 ago 2023
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an au
23RIESGO
abrir
Metasploit600
CrushFTP Unauthenticated RCE
CVE-2023-4317708 ago 2023
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes
60RIESGO
abrir
Metasploit600
LG Simple Editor Command Injection (CVE-2023-40504)
CVE-2023-40504CRITICAL04 ago 2023
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability
65RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.