Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.041exploits catalogados
32.227CVEs con explotación pública
1932probados en laboratorio
8198 exploits
VulnCheck XDB
infoleak
CVE-2023-27524HIGHbajo ataque11 may 2024
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-3806CRITICAL10 may 2024
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-7169CRITICALbajo ataque10 may 2024
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque10 may 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-3807HIGH10 may 2024
Porto <= 7.1.0 - Authenticated (Contributor+) Local File Inclusion via Post Meta
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware09 may 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware09 may 2024
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-999509 may 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALbajo ataque08 may 2024
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware08 may 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware07 may 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque05 may 2024
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-9670CRITICALbajo ataque05 may 2024
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque04 may 2024
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware03 may 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALbajo ataque03 may 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL03 may 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27971HIGH03 may 2024
WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.10 - Local File Inclusion vulnerability
41RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-21413CRITICALbajo ataque03 may 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALbajo ataque01 may 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque01 may 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL01 may 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque01 may 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware30 abr 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware30 abr 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALbajo ataque30 abr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware30 abr 2024
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-1086HIGHbajo ataqueransomware30 abr 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALbajo ataque29 abr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque28 abr 2024
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
anteriorpágina 128 / 274siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.