Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
81.759 exploits
VulnCheck XDB
infoleak
CVE-2024-4956HIGH23 oct 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2017-8917—23 oct 2024
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗
GitHub PoC★ 1
bueno-armando/CVE-2023-4220-RCE
CVE-2023-4220HIGH23 oct 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗
GitHub PoC
rahisec/CVE-2024-4040
CVE-2024-4040CRITICALbajo ataque23 oct 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗
GitHub PoC★ 2
CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH.
CVE-2024-6387HIGH22 oct 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-5522MEDIUM22 oct 2024
HTML5 Video Player < 2.5.27 - Unauthenticated SQLi
48RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-5522MEDIUM22 oct 2024
HTML5 Video Player < 2.5.27 - Unauthenticated SQLi
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware22 oct 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALbajo ataque22 oct 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-49070—22 oct 2024
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-5360—22 oct 2024
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-2523HIGH22 oct 2024
Weaver E-Office unrestricted upload
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALbajo ataque22 oct 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware22 oct 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALbajo ataqueransomware22 oct 2024
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗
GitHub PoC★ 1
grecosamuel/CVE-2024-32002
CVE-2024-32002CRITICAL22 oct 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM22 oct 2024
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-26067HIGH22 oct 2024
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
68RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-2648MEDIUM22 oct 2024
Weaver E-Office uploadify.php unrestricted upload
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque22 oct 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-1663CRITICAL22 oct 2024
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-35078CRITICALbajo ataqueransomware22 oct 2024
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2019-11358—22 oct 2024
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-3272CRITICALbajo ataque22 oct 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4577CRITICALbajo ataqueransomware22 oct 2024
Argument Injection in PHP-CGI
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware22 oct 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALbajo ataque22 oct 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2022-44149HIGH22 oct 2024
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by
53RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4956HIGH22 oct 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4956HIGH22 oct 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗
← anteriorpágina 411 / 2726siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.