Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
81.759 exploits
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALbajo ataqueransomware22 oct 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware22 oct 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-28771CRITICALbajo ataque22 oct 2024
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque22 oct 2024
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALbajo ataque22 oct 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware22 oct 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware22 oct 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2024-4956HIGH22 oct 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4956HIGH22 oct 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4956HIGH22 oct 2024
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-27925HIGHbajo ataqueransomware22 oct 2024
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque22 oct 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque22 oct 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL22 oct 2024
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM22 oct 2024
Cross site scripting
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque22 oct 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware22 oct 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque22 oct 2024
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware22 oct 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware22 oct 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-49070—22 oct 2024
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware22 oct 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALbajo ataque22 oct 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-2523HIGH22 oct 2024
Weaver E-Office unrestricted upload
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-5360—22 oct 2024
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗
GitHub PoC★ 1
grecosamuel/CVE-2024-32002
CVE-2024-32002CRITICAL22 oct 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware22 oct 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALbajo ataqueransomware22 oct 2024
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALbajo ataque22 oct 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware22 oct 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗
← anteriorpágina 412 / 2726siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.