Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
76.313 exploits
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALbajo ataque22 oct 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
GitHub PoC2
CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH.
CVE-2024-6387HIGH22 oct 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware22 oct 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque21 oct 2024
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-21683HIGH21 oct 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RIESGO
abrir
GitHub PoC39
Grafana RCE exploit (CVE-2024-9264)
CVE-2024-9264CRITICAL21 oct 2024
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC
punitdarji/Grafana-CVE-2024-9264
CVE-2024-9264CRITICAL21 oct 2024
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware21 oct 2024
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-536021 oct 2024
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC11
p33d/CVE-2024-23113
CVE-2024-23113CRITICALbajo ataque21 oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir
VulnCheck XDB
local
CVE-2023-32784HIGH21 oct 2024
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-47253CRITICAL21 oct 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHbajo ataqueransomware21 oct 2024
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque21 oct 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware21 oct 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL21 oct 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque21 oct 2024
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23113CRITICALbajo ataque21 oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-16651HIGHbajo ataque21 oct 2024
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RIESGO
abrir
VulnCheck XDB
local
CVE-2024-35250HIGHbajo ataque21 oct 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir
GitHub PoC5
Arbitrary File Read and DoS in vendure-ecommerce exploit
CVE-2024-48914CRITICAL21 oct 2024
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
75RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-48914CRITICAL21 oct 2024
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
75RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM21 oct 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM20 oct 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC7
File Read Proof of Concept for CVE-2024-9264
CVE-2024-9264CRITICAL20 oct 2024
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC5
Proof-of-Concept for LFI/Path Traversal vulnerability in Aiohttp =< 3.9.1
CVE-2024-23334MEDIUM20 oct 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC1
Affected versions of this package are vulnerable to Race Condition. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely.
CVE-2021-32708CRITICAL19 oct 2024
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
48RIESGO
abrir
Metasploit300
OneDev Unauthenticated Arbitrary File Read
CVE-2024-45309HIGH19 oct 2024
OneDev vulnerable to arbitrary file reading for unauthenticated user
41RIESGO
abrir
GitHub PoC132
Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)
CVE-2024-9264CRITICAL19 oct 2024
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC2
Security Bulletin for CVE-2024-35133 - With PoC
CVE-2024-35133MEDIUM18 oct 2024
IBM Security Verify Access HTTP open redirect
33RIESGO
abrir
anteriorpágina 338 / 2544siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.