Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
8195 exploits
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware28 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3398HIGHbajo ataque28 ene 2024
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864628 ene 2024
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-6933HIGH28 ene 2024
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque28 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque27 ene 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-6875CRITICAL27 ene 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware27 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 ene 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque26 ene 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque26 ene 2024
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-19410CRITICALbajo ataque25 ene 2024
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privile
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware25 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46805HIGHbajo ataqueransomware25 ene 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware25 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware25 ene 2024
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-0204CRITICAL24 ene 2024
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0787HIGHbajo ataqueransomware24 ene 2024
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-4262HIGHbajo ataque24 ene 2024
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corru
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware24 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
local
CVE-2017-1315624 ene 2024
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware24 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware23 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware23 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware23 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware23 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALbajo ataqueransomware23 ene 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
anteriorpágina 137 / 274siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.