Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
77.058 exploits
GitHub PoC
corelight/CVE-2021-38647-noimages
CVE-2021-38647CRITICALbajo ataqueransomware13 mar 2024
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
WordPress wp-automatic Plugin SQLi Admin Creation
CVE-2024-27956CRITICAL13 mar 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2024-21762CRITICALbajo ataqueransomware13 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-21762CRITICALbajo ataqueransomware13 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware12 mar 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC1
CVE-2023-23752 Data Extractor
CVE-2023-23752MEDIUMbajo ataque12 mar 2024
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMbajo ataque12 mar 2024
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
Metasploit600
NorthStar C2 XSS to Agent RCE
CVE-2024-28741HIGH12 mar 2024
Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code
58RIESGO
abrir
Metasploit300
CVE-2024-20767 - Adobe Coldfusion Arbitrary File Read
CVE-2024-20767HIGHbajo ataque12 mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC42
Proof-of-concept exploit for CVE-2024-25153.
CVE-2024-25153CRITICAL12 mar 2024
Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
60RIESGO
abrir
GitHub PoC3
hienkiet/CVE-2022-21445-for-12.2.1.3.0-Weblogic
CVE-2022-21445CRITICALbajo ataque12 mar 2024
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
90RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-21445CRITICALbajo ataque12 mar 2024
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
90RIESGO
abrir
GitHub PoC92
Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)
CVE-2024-29059HIGHbajo ataque11 mar 2024
.NET Framework Information Disclosure Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-29059HIGHbajo ataque11 mar 2024
.NET Framework Information Disclosure Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-21762CRITICALbajo ataqueransomware11 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
GitHub PoC
CSV Injection in Addactis IBNRS 3.10.3.107
CVE-2024-29375CRITICAL11 mar 2024
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a craf
48RIESGO
abrir
Exploit-DB
Ladder v0.0.21 - Server-side request forgery (SSRF)
CVE-2024-27620HIGHwebappsgo10 mar 2024
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request
41RIESGO
abrir
Exploit-DB
Hide My WP < 6.2.9 - Unauthenticated SQLi
CVE-2022-4681CRITICALwebappsphp10 mar 2024
Hide My WP < 6.2.9 - Unauthenticated SQLi
48RIESGO
abrir
Exploit-DB
Numbas < v7.3 - Remote Code Execution
CVE-2024-27612MEDIUMwebappsnodejs10 mar 2024
Numbas editor before 7.3 mishandles editing of themes and extensions.
38RIESGO
abrir
Exploit-DB
DataCube3 v1.0 - Unrestricted file upload 'RCE'
CVE-2024-25832HIGHwebappsphp10 mar 2024
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to
46RIESGO
abrir
GitHub PoC17
Demo showing Claude Opus does not find CVE-2023-0266
CVE-2023-0266HIGHbajo ataque10 mar 2024
Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel
71RIESGO
abrir
Exploit-DB
Akaunting < 3.1.3 - RCE
CVE-2024-22836CRITICALwebappsphp10 mar 2024
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company loc
60RIESGO
abrir
Exploit-DB
DataCube3 v1.0 - Unrestricted file upload 'RCE'
CVE-2024-25830CRITICALwebappsphp10 mar 2024
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una
53RIESGO
abrir
GitHub PoC1
CharonDefalt/CVE-2024-27198-RCE
CVE-2024-27198CRITICALbajo ataqueransomware09 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC8
A PoC exploit for CVE-2024-27198 - JetBrains TeamCity Authentication Bypass
CVE-2024-27198CRITICALbajo ataqueransomware09 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALbajo ataqueransomware09 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALbajo ataqueransomware09 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALbajo ataqueransomware08 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
CVE-2019-1722508 mar 2024
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i
23RIESGO
abrir
GitHub PoC2
https://github.com/Phamchie/CVE-2023-3047
CVE-2023-3047CRITICAL08 mar 2024
SQLi in TMT's Lockcell
48RIESGO
abrir
anteriorpágina 417 / 2569siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.