Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
77.058 exploits
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware17 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALbajo ataqueransomware17 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
GitHub PoC12
The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.
CVE-2024-21762CRITICALbajo ataqueransomware17 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
GitHub PoC7
jakabakos/CVE-2023-43208-mirth-connect-rce-poc
CVE-2023-43208CRITICALbajo ataqueransomware17 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC4
sxyrxyy/aiohttp-exploit-CVE-2024-23334-certstream
CVE-2024-23334MEDIUM17 mar 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
Metasploit600
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
CVE-2024-24578CRITICAL16 mar 2024
RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
43RIESGO
abrir
Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
CVE-2024-28254HIGH15 mar 2024
SpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadata
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware15 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
CVE-2024-28255CRITICAL15 mar 2024
Authentication Bypass in OpenMetadata
85RIESGO
abrir
GitHub PoC3
Exploit for Open eClass – CVE-2024-26503: Unrestricted File Upload Leads to Remote Code Execution
CVE-2024-26503CRITICAL15 mar 2024
Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to
48RIESGO
abrir
GitHub PoC
exploit for f5-big-ip RCE cve-2023-46747
CVE-2023-46747CRITICALbajo ataqueransomware15 mar 2024
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-44228CRITICALbajo ataqueransomware15 mar 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC29
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
CVE-2023-43208CRITICALbajo ataqueransomware15 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21626HIGH15 mar 2024
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir
GitHub PoC
This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).
CVE-2021-44228CRITICALbajo ataqueransomware15 mar 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
SolarView Compact 6.00 - Command Injection
CVE-2023-23333CRITICALremotehardware14 mar 2024
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
Exploit-DB
GitLab CE/EE < 16.7.2 - Password Reset
CVE-2023-7028CRITICALbajo ataqueremotejava14 mar 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
Metasploit600
Ghostscript Command Execution via Format String
CVE-2024-29510MEDIUM14 mar 2024
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with
33RIESGO
abrir
Exploit-DB
KiTTY 0.76.1.13 - Command Injection
CVE-2024-23749HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RIESGO
abrir
Exploit-DB
Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)
CVE-2023-3710CRITICALremotehardware14 mar 2024
Printer web page invalid command execution
75RIESGO
abrir
GitHub PoC
manrop2702/CVE-2020-7961
CVE-2020-7961CRITICALbajo ataque14 mar 2024
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC
A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.
CVE-2023-20048CRITICAL14 mar 2024
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
53RIESGO
abrir
Exploit-DB
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
CVE-2023-42793CRITICALbajo ataqueransomwareremotejava14 mar 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5222MEDIUMremotehardware14 mar 2024
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RIESGO
abrir
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
CVE-2024-25004HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf
41RIESGO
abrir
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5702MEDIUMremotehardware14 mar 2024
Viessmann Vitogate 300 direct request
38RIESGO
abrir
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
CVE-2024-25003HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALbajo ataque14 mar 2024
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC150
out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability
CVE-2024-21762CRITICALbajo ataqueransomware13 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
GitHub PoC16
Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)
CVE-2024-21762CRITICALbajo ataqueransomware13 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
anteriorpágina 416 / 2569siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.