Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
76.559 exploits
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque22 jul 2024
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALbajo ataque21 jul 2024
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-6205HIGH21 jul 2024
PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware21 jul 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC
CVE 2023-22515
CVE-2023-22515CRITICALbajo ataqueransomware21 jul 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC
Educational exploit for CVE-2022-30190
CVE-2022-30190HIGHbajo ataqueransomware20 jul 2024
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
TSY244/CVE-2024-32002-git-rce
CVE-2024-32002CRITICAL20 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
Metasploit300
Cisco Smart Software Manager (SSM) On-Prem Account Takeover (CVE-2024-20419)
CVE-2024-20419CRITICAL20 jul 2024
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
85RIESGO
abrir
GitHub PoC
TSY244/CVE-2024-32002-git-rce-father-poc
CVE-2024-32002CRITICAL20 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
HPT-Intern-Task-Submission/CVE-2024-27198
CVE-2024-27198CRITICALbajo ataqueransomware20 jul 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-30190HIGHbajo ataqueransomware20 jul 2024
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALbajo ataqueransomware20 jul 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-139719 jul 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir
Metasploit600
ProjectSend r1295 - r1605 Unauthenticated Remote Code Execution
CVE-2024-11680CRITICALbajo ataque19 jul 2024
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
GitHub PoC
CVE-2022-37706-Enlightenment v0.25.3 - Privilege escalation
CVE-2022-37706HIGH19 jul 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC
Wytchwulf/CVE-2015-1397-Magento-Shoplift
CVE-2015-139719 jul 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-11317CRITICALbajo ataque18 jul 2024
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-11357CRITICALbajo ataqueransomware18 jul 2024
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware18 jul 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC4
Vulnerability checking tool via Nmap Scripting Engine
CVE-2023-22515CRITICALbajo ataqueransomware18 jul 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC2
Proof Of Concept for CVE-2024-1874
CVE-2024-1874CRITICAL18 jul 2024
Command injection via array-ish $command parameter of proc_open()
60RIESGO
abrir
GitHub PoC3
Exploit for CVE-2024-31989.
CVE-2024-31989CRITICAL17 jul 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALbajo ataque17 jul 2024
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque17 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC1
Script para eliminar vulnerabilidad de openssh de ubuntu 22.04 LTS
CVE-2023-38408CRITICAL17 jul 2024
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC43
geoserver CVE-2024-36401漏洞利用工具
CVE-2024-36401CRITICALbajo ataque17 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC
Automated PHP remote code execution scanner for CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware16 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware16 jul 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware16 jul 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
khanhtranngoccva/cve-2023-38831-poc
CVE-2023-38831HIGHbajo ataqueransomware16 jul 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
anteriorpágina 365 / 2552siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.