Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Openfire authentication bypass with RCE plugin
CVE-2023-32315HIGHbajo ataque26 may 2023
Openfire administration console authentication bypass
100RIESGO
abrir
Metasploit300
GitLab Authenticated File Read
CVE-2023-2825CRITICAL23 may 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
Metasploit600
Apache RocketMQ update config RCE
CVE-2023-33246CRITICALbajo ataque23 may 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
Metasploit600
Barracuda ESG TAR Filename Command Injection
CVE-2023-2868CRITICALbajo ataque23 may 2023
Remote Code injection in Barracuda Email Security Gateway
100RIESGO
abrir
Metasploit600
Delta Electronics InfraSuite Device Master Deserialization
CVE-2023-1133CRITICAL17 may 2023
CVE-2023-1133
75RIESGO
abrir
Metasploit600
SolarView Compact unauthenticated remote command execution vulnerability.
CVE-2023-23333CRITICAL15 may 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
Metasploit600
TOTOLINK Wireless Routers unauthenticated remote command execution vulnerability.
CVE-2023-30013CRITICAL05 may 2023
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/s
68RIESGO
abrir
Metasploit600
Sharepoint Dynamic Proxy Generator Unauth RCE
CVE-2023-29357CRITICALbajo ataqueransomware01 may 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
Sharepoint Dynamic Proxy Generator Unauth RCE
CVE-2023-24955HIGHbajo ataqueransomware01 may 2023
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit300
Apache Superset Signed Cookie Priv Esc
CVE-2023-27524HIGHbajo ataque25 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
Metasploit600
Ivanti Avalanche FileStoreConfig File Upload
CVE-2023-28128HIGH24 abr 2023
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could
58RIESGO
abrir
Metasploit600
invscout RPM Privilege Escalation
CVE-2023-28528HIGH24 abr 2023
IBM AIX command execution
36RIESGO
abrir
Metasploit300
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
CVE-2023-26876HIGH21 abr 2023
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via t
36RIESGO
abrir
Metasploit600
ManageEngine ADManager Plus ChangePasswordAction Authenticated Command Injection
CVE-2023-29084HIGH12 abr 2023
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy setti
58RIESGO
abrir
Metasploit300
CVE-2023-21554 - QueueJumper - MSMQ RCE Check
CVE-2023-21554CRITICAL11 abr 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RIESGO
abrir
Metasploit400
Windows Common Log File System Driver (clfs.sys) Elevation of Privilege Vulnerability
CVE-2023-28252HIGHbajo ataqueransomware11 abr 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir
Metasploit300
Jasmin Ransomware Web Server Unauthenticated SQL Injection
CVE-2025-6095MEDIUM08 abr 2023
codesiddhant Jasmin Ransomware checklogin.php sql injection
28RIESGO
abrir
Metasploit300
Jasmin Ransomware Web Server Unauthenticated Directory Traversal
CVE-2024-30851MEDIUM08 abr 2023
Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive infor
28RIESGO
abrir
Metasploit300
ThinManager Path Traversal (CVE-2023-27856) Arbitrary File Download
CVE-2023-27856HIGH05 abr 2023
Rockwell Automation ThinManager ThinServer Path Traversal Download
58RIESGO
abrir
Metasploit300
ThinManager Path Traversal (CVE-2023-27855) Arbitrary File Upload
CVE-2023-27855CRITICAL05 abr 2023
Rockwell Automation ThinManager ThinServer Path Traversal Upload
48RIESGO
abrir
Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
CVE-2022-43769HIGHbajo ataque04 abr 2023
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RIESGO
abrir
Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
CVE-2022-43939HIGHbajo ataque04 abr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RIESGO
abrir
Metasploit500
Zyxel IKE Packet Decoder Unauthenticated Remote Code Execution
CVE-2023-28771CRITICALbajo ataque31 mar 2023
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir
Metasploit600
Nextcloud Workflows Remote Code Execution
CVE-2023-26482CRITICAL30 mar 2023
Scope of workflow operations is not validated in nextcloud server
63RIESGO
abrir
Metasploit600
Rocket Software Unidata udadmin_server Authentication Bypass
CVE-2023-28503CRITICAL30 mar 2023
Authentication bypass in UniRPC's udadmin service
75RIESGO
abrir
Metasploit400
Rocket Software Unidata udadmin_server Stack Buffer Overflow in Password
CVE-2023-28502CRITICAL30 mar 2023
Stack buffer overflow in UniRPC's udadmin_server service
75RIESGO
abrir
Metasploit300
Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation
CVE-2023-2812122 mar 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RIESGO
abrir
Metasploit600
Local Privilege Escalation via CVE-2023-0386
CVE-2023-0386HIGHbajo ataque22 mar 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
Metasploit300
MinIO Bootstrap Verify Information Disclosure
CVE-2023-28432HIGHbajo ataque20 mar 2023
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir
Metasploit600
pfSense Restore RRD Data Command Injection
CVE-2023-2725318 mar 2023
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attac
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.