Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
CVE-2022-29464
CVE-2022-29464CRITICALbajo ataqueransomware
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
Referência
CVE-2021-35464
CVE-2021-35464CRITICALbajo ataqueransomware
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir
Referência
CVE-2021-35464
CVE-2021-35464CRITICALbajo ataqueransomware
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir
Referência
CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
Referência
CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
Referência
CVE-2023-4966
CVE-2023-4966CRITICALbajo ataqueransomware
Unauthenticated sensitive information disclosure
100RIESGO
abrir
Referência
CVE-2022-26134
CVE-2022-26134CRITICALbajo ataqueransomware
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
Referência
CVE-2023-22518
CVE-2023-22518CRITICALbajo ataqueransomware
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir
Referência
CVE-2021-1498
CVE-2021-1498CRITICALbajo ataque
Cisco HyperFlex HX Command Injection Vulnerabilities
100RIESGO
abrir
Referência
CVE-2023-27350
CVE-2023-27350CRITICALbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
Referência
CVE-2023-27350
CVE-2023-27350CRITICALbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
Referência
CVE-2023-27350
CVE-2023-27350CRITICALbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
Referência
CVE-2023-27350
CVE-2023-27350CRITICALbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
Referência
CVE-2023-0669
CVE-2023-0669HIGHbajo ataqueransomware
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RIESGO
abrir
Referência
CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Referência
CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Referência
CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Referência
CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Referência
CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Referência
CVE-2021-43798
CVE-2021-43798HIGHbajo ataque
Grafana path traversal
100RIESGO
abrir
Referência
CVE-2019-11510
CVE-2019-11510CRITICALbajo ataqueransomware
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Referência
CVE-2019-11510
CVE-2019-11510CRITICALbajo ataqueransomware
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Referência
CVE-2024-0723
freeSSHd denial of service
33RIESGO
abrir
Referência
CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Referência
CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Referência
CVE-2016-10010
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which
41RIESGO
abrir
Referência
CVE-2021-43857
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
anteriorpágina 257 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.