Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
77.302 exploits
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware03 jul 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
CVE-2023-28285HIGHremotemultiple03 jul 2023
Microsoft Office Remote Code Execution Vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-32315HIGHbajo ataque02 jul 2023
Openfire administration console authentication bypass
100RIESGO
abrir
GitHub PoC1
Expoit for CVE-2022-44268
CVE-2022-44268MEDIUM02 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC6
Perform With Massive Openfire Unauthenticated Users
CVE-2023-32315HIGHbajo ataque02 jul 2023
Openfire administration console authentication bypass
100RIESGO
abrir
Metasploit600
OpenNMS Horizon Authenticated RCE
CVE-2023-40315MEDIUM01 jul 2023
ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN
28RIESGO
abrir
Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
CVE-2023-36812CRITICAL01 jul 2023
Remote Code Execution in OpenTSDB
68RIESGO
abrir
Metasploit600
OpenNMS Horizon Authenticated RCE
CVE-2023-0872HIGH01 jul 2023
ROLE_REST can be used to escalate to ROLE_ADMIN via /rest/users
36RIESGO
abrir
Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
CVE-2023-25826CRITICAL01 jul 2023
Remote Code Execution in OpenTSDB
75RIESGO
abrir
GitHub PoC5
Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi
CVE-2014-6271CRITICALbajo ataque01 jul 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque01 jul 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL01 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM01 jul 2023
Cross site scripting
70RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM01 jul 2023
Cross site scripting
70RIESGO
abrir
GitHub PoC
spip
CVE-2023-27372CRITICAL01 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC9
WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证
CVE-2023-2982CRITICAL30 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir
GitHub PoC11
Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).
CVE-2019-6693MEDIUMbajo ataqueransomware30 jun 2023
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RIESGO
abrir
VulnCheck XDB
local
CVE-2020-104830 jun 2023
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-2982CRITICAL30 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-2982CRITICAL29 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-42013CRITICALbajo ataqueransomware29 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware29 jun 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC82
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
CVE-2023-2982CRITICAL29 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RIESGO
abrir
GitHub PoC
yangshifan-git/CVE-2021-1732
CVE-2021-1732HIGHbajo ataqueransomware29 jun 2023
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC4
Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.
CVE-2021-44228CRITICALbajo ataqueransomware29 jun 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Hamesawian/CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware29 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHbajo ataque28 jun 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-2625828 jun 2023
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe
50RIESGO
abrir
VulnCheck XDB
local
CVE-2023-3269HIGH28 jun 2023
Distros-[dirtyvma] privilege escalation via non-rcu-protected vma traversal
41RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-287728 jun 2023
Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution
28RIESGO
abrir
anteriorpágina 485 / 2577siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.