Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2025-1094HIGH16 dic 2024
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RIESGO
abrir
Metasploit600
Invoice Ninja unauthenticated PHP Deserialization Vulnerability
CVE-2024-55555HIGH13 dic 2024
Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_
36RIESGO
abrir
Metasploit600
InvoiceShelf unauthenticated PHP Deserialization Vulnerability
CVE-2024-55556CRITICAL13 dic 2024
A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote com
55RIESGO
abrir
Metasploit600
Cleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution
CVE-2024-55956CRITICALbajo ataqueransomware09 dic 2024
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can impo
95RIESGO
abrir
Metasploit300
LINQPad Deserialization
CVE-2024-53326HIGH03 dic 2024
LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(
36RIESGO
abrir
Metasploit600
mySCADA myPRO Manager Unauthenticated Command Injection (CVE-2024-47407)
CVE-2024-47407CRITICAL21 nov 2024
mySCADA myPRO OS Command Injection
55RIESGO
abrir
Metasploit600
Pandora FMS authenticated command injection leading to RCE via LDAP using default DB password
CVE-2024-11320MEDIUM21 nov 2024
Command Injection leading to RCE via LDAP Misconfiguration
50RIESGO
abrir
Metasploit500
Ubuntu needrestart Privilege Escalation
CVE-2024-48990HIGH19 nov 2024
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tric
41RIESGO
abrir
Metasploit600
Palo Alto Networks PAN-OS Management Interface Unauthenticated Remote Code Execution
CVE-2024-9474MEDIUMbajo ataqueransomware18 nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
Metasploit600
Palo Alto Networks PAN-OS Management Interface Unauthenticated Remote Code Execution
CVE-2024-0012CRITICALbajo ataqueransomware18 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
Metasploit600
LibreNMS Authenticated RCE (CVE-2024-51092)
CVE-2024-51092CRITICAL15 nov 2024
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr
43RIESGO
abrir
Metasploit600
WordPress WP Time Capsule Arbitrary File Upload to RCE
CVE-2024-8856CRITICAL15 nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir
Metasploit600
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
CVE-2024-10924CRITICAL14 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
Metasploit600
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
CVE-2024-28397MEDIUM28 oct 2024
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
Metasploit600
Prison Management System 1.0 Authenticated RCE via Unrestricted File Upload
CVE-2024-48594HIGH28 oct 2024
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the f
36RIESGO
abrir
Metasploit600
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
CVE-2024-39205CRITICAL28 oct 2024
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RIESGO
abrir
Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CVE-2024-51378CRITICALbajo ataqueransomware27 oct 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CVE-2024-51568CRITICAL27 oct 2024
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RIESGO
abrir
Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CVE-2024-51567CRITICALbajo ataqueransomware27 oct 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir
Metasploit600
Fortinet FortiManager Unauthenticated RCE
CVE-2024-47575CRITICALbajo ataque23 oct 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir
Metasploit300
OneDev Unauthenticated Arbitrary File Read
CVE-2024-45309HIGH19 oct 2024
OneDev vulnerable to arbitrary file reading for unauthenticated user
41RIESGO
abrir
Metasploit600
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
CVE-2024-5910CRITICALbajo ataque09 oct 2024
Expedition: Missing Authentication Leads to Admin Account Takeover
100RIESGO
abrir
Metasploit600
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
CVE-2024-24809HIGH09 oct 2024
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RIESGO
abrir
Metasploit600
Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection
CVE-2024-37404CRITICAL08 oct 2024
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Se
55RIESGO
abrir
Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
CVE-2024-47175HIGH26 sep 2024
libppd's ppdCreatePPDFromIPP2 function does not sanitize IPP attributes when creating the PPD buffer
48RIESGO
abrir
Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
CVE-2024-47176MEDIUM26 sep 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
CVE-2024-4717726 sep 2024
15RIESGO
abrir
Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
CVE-2024-47076HIGH26 sep 2024
libcupsfilters's cfGetPrinterAttributes5 does not validate IPP attributes returned from an IPP server
58RIESGO
abrir
Metasploit300
WordPress TI WooCommerce Wishlist SQL Injection (CVE-2024-43917)
CVE-2024-43917CRITICAL25 sep 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RIESGO
abrir
Metasploit300
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
CVE-2024-8529CRITICAL11 sep 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.