Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Adobe ColdFusion Unauthenticated Remote Code Execution
CVE-2023-26360HIGHbajo ataque14 mar 2023
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
Metasploit300
Dolibarr 16 pre-auth contact database dump
CVE-2023-3356814 mar 2023
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's
23RIESGO
abrir
Metasploit600
Lexmark Device Embedded Web Server RCE
CVE-2023-26068CRITICAL13 mar 2023
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
68RIESGO
abrir
Metasploit600
PaperCut PaperCutNG Authentication Bypass
CVE-2023-27350CRITICALbajo ataqueransomware13 mar 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
Metasploit300
Pretalx Arbitrary File Read/Limited File Write
CVE-2023-28459MEDIUM07 mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload craft
28RIESGO
abrir
Metasploit300
Pretalx Arbitrary File Read/Limited File Write
CVE-2023-28458MEDIUM07 mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RIESGO
abrir
Metasploit600
Pretalx Limited File Write to Remote Code Execution
CVE-2023-28458MEDIUM07 mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RIESGO
abrir
Metasploit600
SPIP form PHP Injection
CVE-2023-27372CRITICAL27 feb 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
Metasploit600
ZoneMinder Snapshots Command Injection
CVE-2023-26035HIGH24 feb 2023
ZoneMinder vulnerable to Missing Authorization
58RIESGO
abrir
Metasploit300
RPyC 4.1.0 through 4.1.1 Remote Command Execution
CVE-2019-1632819 feb 2023
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure
23RIESGO
abrir
Metasploit600
Fortinet FortiNAC keyUpload.jsp arbitrary file write
CVE-2022-39952CRITICAL16 feb 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RIESGO
abrir
Metasploit600
Lucee Authenticated Scheduled Job Code Execution
CVE-2025-34074CRITICAL10 feb 2023
Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
63RIESGO
abrir
Metasploit600
Apache Druid JNDI Injection RCE
CVE-2023-25194HIGH07 feb 2023
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RIESGO
abrir
Metasploit300
Joomla API Improper Access Checks
CVE-2023-23752MEDIUMbajo ataque01 feb 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
Metasploit600
Fortra GoAnywhere MFT Unsafe Deserialization RCE
CVE-2023-0669HIGHbajo ataqueransomware01 feb 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RIESGO
abrir
Metasploit600
Froxlor Log Path RCE
CVE-2023-0315HIGH29 ene 2023
Command Injection in froxlor/froxlor
78RIESGO
abrir
Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
CVE-2022-31706CRITICAL24 ene 2023
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi
85RIESGO
abrir
Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
CVE-2022-31711MEDIUM24 ene 2023
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sen
53RIESGO
abrir
Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
CVE-2022-31704CRITICAL24 ene 2023
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
85RIESGO
abrir
Metasploit600
Sudoedit Extra Arguments Priv Esc
CVE-2023-22809HIGH18 ene 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
Metasploit600
Oracle Weblogic PreAuth Remote Command Execution via ForeignOpaqueReference IIOP Deserialization
CVE-2023-21839HIGHbajo ataque17 ene 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
Metasploit600
pyLoad js2py Python Execution
CVE-2023-0297CRITICAL13 ene 2023
Code Injection in pyload/pyload
85RIESGO
abrir
Metasploit300
Wordpress Paid Membership Pro code Unauthenticated SQLi
CVE-2023-23488CRITICAL12 ene 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir
Metasploit600
Ancillary Function Driver (AFD) for WinSock Elevation of Privilege
CVE-2023-21768HIGH10 ene 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RIESGO
abrir
Metasploit600
ManageEngine ADSelfService Plus Unauthenticated SAML RCE
CVE-2022-47966CRITICALbajo ataqueransomware10 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
Metasploit600
ManageEngine ServiceDesk Plus Unauthenticated SAML RCE
CVE-2022-47966CRITICALbajo ataqueransomware10 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
Metasploit600
ManageEngine Endpoint Central Unauthenticated SAML RCE
CVE-2022-47966CRITICALbajo ataqueransomware10 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
Metasploit600
Jorani unauthenticated Remote Code Execution
CVE-2023-2646906 ene 2023
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
60RIESGO
abrir
Metasploit600
CWP login.php Unauthenticated RCE
CVE-2022-44877CRITICALbajo ataque05 ene 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RIESGO
abrir
Metasploit400
SugarCRM unauthenticated Remote Code Execution (RCE)
CVE-2023-22952HIGHbajo ataque28 dic 2022
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because o
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.