Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Eramba (up to 3.19.1) Authenticated Remote Code Execution Module
CVE-2023-3625501 ago 2023
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrar
30RIESGO
abrir
Metasploit600
Maltrail Unauthenticated Command Injection
CVE-2025-34073CRITICAL31 jul 2023
stamparm/maltrail <=0.54 Remote Command Execution
63RIESGO
abrir
Metasploit600
RaspAP Unauthenticated Command Injection
CVE-2022-3998631 jul 2023
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary comma
60RIESGO
abrir
Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
CVE-2023-2640HIGH26 jul 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RIESGO
abrir
Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
CVE-2023-32629HIGH26 jul 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RIESGO
abrir
Metasploit600
Greenshot .NET Deserialization Fileformat Exploit
CVE-2023-3463426 jul 2023
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green
38RIESGO
abrir
Metasploit600
Metabase Setup Token RCE
CVE-2023-3864622 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
Metasploit300
Citrix ADC (NetScaler) Forms SSO Target RCE
CVE-2023-3519CRITICALbajo ataqueransomware18 jul 2023
Unauthenticated remote code execution
100RIESGO
abrir
Metasploit600
BoidCMS Command Injection
CVE-2023-3883613 jul 2023
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header t
60RIESGO
abrir
Metasploit600
Sonicwall
CVE-2023-34127HIGH12 jul 2023
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GM
58RIESGO
abrir
Metasploit600
Sonicwall
CVE-2023-34133HIGH12 jul 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and
58RIESGO
abrir
Metasploit600
Sonicwall
CVE-2023-34124CRITICAL12 jul 2023
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
75RIESGO
abrir
Metasploit600
Sonicwall
CVE-2023-3413212 jul 2023
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the
18RIESGO
abrir
Metasploit600
Microsoft Error Reporting Local Privilege Elevation Vulnerability
CVE-2023-36874HIGHbajo ataque11 jul 2023
Windows Error Reporting Service Elevation of Privilege Vulnerability
98RIESGO
abrir
Metasploit600
OpenNMS Horizon Authenticated RCE
CVE-2023-0872HIGH01 jul 2023
ROLE_REST can be used to escalate to ROLE_ADMIN via /rest/users
36RIESGO
abrir
Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
CVE-2023-25826CRITICAL01 jul 2023
Remote Code Execution in OpenTSDB
75RIESGO
abrir
Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
CVE-2023-36812CRITICAL01 jul 2023
Remote Code Execution in OpenTSDB
68RIESGO
abrir
Metasploit600
OpenNMS Horizon Authenticated RCE
CVE-2023-40315MEDIUM01 jul 2023
ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN
28RIESGO
abrir
Metasploit600
MagnusBilling application unauthenticated Remote Command Execution.
CVE-2023-30258CRITICAL26 jun 2023
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
Metasploit600
Rudder Server SQLI Remote Code Execution
CVE-2023-30625HIGH16 jun 2023
rudder-server vulnerable to SQL Injection
58RIESGO
abrir
Metasploit600
Apache NiFi H2 Connection String Remote Code Execution
CVE-2023-34468HIGH12 jun 2023
Apache NiFi: Potential Code Injection with Database Services using H2
48RIESGO
abrir
Metasploit300
MongoDB Ops Manager Diagnostic Archive Sensitive Information Retriever
CVE-2023-0342LOW09 jun 2023
MongoDB Ops Manager may disclose sensitive information in Diagnostic Archive
23RIESGO
abrir
Metasploit600
Ivanti EPM Agent Portal Command Execution
CVE-2023-28324HIGH07 jun 2023
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege es
41RIESGO
abrir
Metasploit600
VMWare Aria Operations for Networks (vRealize Network Insight) pre-authenticated RCE
CVE-2023-20887CRITICALbajo ataque07 jun 2023
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RIESGO
abrir
Metasploit600
CmsMadeSimple Authenticated File Manager RCE
CVE-2023-3696907 jun 2023
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
30RIESGO
abrir
Metasploit600
Splunk "edit_user" Capability Privilege Escalation
CVE-2023-32707HIGH01 jun 2023
‘edit_user’ Capability Privilege Escalation
78RIESGO
abrir
Metasploit600
Chamilo unauthenticated command injection in PowerPoint upload
CVE-2023-3496001 jun 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RIESGO
abrir
Metasploit600
MOVEit SQL Injection vulnerability
CVE-2023-34362CRITICALbajo ataqueransomware31 may 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
Metasploit600
Wordpress File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution through shortcode
CVE-2023-206831 may 2023
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RIESGO
abrir
Metasploit600
Dolibarr ERP/CRM Authenticated Code Injection
CVE-2023-30253HIGH29 may 2023
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instea
58RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.