Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
CVE-2024-8522CRITICAL11 sep 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RIESGO
abrir
Metasploit600
VICIdial Authenticated Remote Code Execution
CVE-2024-8504HIGH10 sep 2024
VICIdial Authenticated Remote Code Execution
58RIESGO
abrir
Metasploit300
Vicidial SQL Injection Time-based Admin Credentials Enumeration
CVE-2024-8503CRITICAL10 sep 2024
VICIdial Unauthenticated SQL Injection
85RIESGO
abrir
Metasploit600
SPIP BigUp Plugin Unauthenticated RCE
CVE-2024-8517CRITICAL06 sep 2024
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir
Metasploit600
Wordpress LiteSpeed Cache plugin cookie theft
CVE-2024-44000CRITICAL04 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
Metasploit300
WhatsUp Gold SQL Injection (CVE-2024-6670)
CVE-2024-6670CRITICALbajo ataqueransomware29 ago 2024
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RIESGO
abrir
Metasploit600
Moodle Remote Code Execution (CVE-2024-43425)
CVE-2024-43425HIGH27 ago 2024
Moodle: remote code execution via calculated question types
78RIESGO
abrir
Metasploit600
GiveWP Unauthenticated Donation Process Exploit
CVE-2024-8353CRITICAL25 ago 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RIESGO
abrir
Metasploit600
GiveWP Unauthenticated Donation Process Exploit
CVE-2024-5932CRITICAL25 ago 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir
Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
CVE-2024-24809HIGH23 ago 2024
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RIESGO
abrir
Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
CVE-2024-31214CRITICAL23 ago 2024
Traccar's unrestricted file upload vulnerability in device image upload could lead to remote code execution
48RIESGO
abrir
Metasploit300
SolarWinds Web Help Desk Backdoor (CVE-2024-28987)
CVE-2024-28987CRITICALbajo ataque22 ago 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
Metasploit600
SPIP Unauthenticated RCE via porte_plume Plugin
CVE-2024-7954CRITICAL16 ago 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
CVE-2024-45257HIGH15 ago 2024
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi
36RIESGO
abrir
Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
CVE-2024-45256CRITICAL15 ago 2024
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overw
43RIESGO
abrir
Metasploit300
Camaleon CMS Directory Traversal CVE-2024-46987
CVE-2024-46987HIGH08 ago 2024
Arbitrary path traversal in Camaleon CMS
61RIESGO
abrir
Metasploit500
Asterisk AMI Originate Authenticated RCE
CVE-2024-42365HIGH08 ago 2024
Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
36RIESGO
abrir
Metasploit300
Ivanti Virtual Traffic Manager Authentication Bypass (CVE-2024-7593)
CVE-2024-7593CRITICALbajo ataque05 ago 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RIESGO
abrir
Metasploit600
Calibre Python Code Injection (CVE-2024-6782)
CVE-2024-6782CRITICAL31 jul 2024
Calibre Remote Code Execution
85RIESGO
abrir
Metasploit600
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
CVE-2024-34102CRITICALbajo ataque26 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
Metasploit600
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
CVE-2024-2961HIGH26 jul 2024
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir
Metasploit600
Acronis Cyber Infrastructure default password remote code execution
CVE-2023-45249CRITICALbajo ataque24 jul 2024
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
85RIESGO
abrir
Metasploit300
Cisco Smart Software Manager (SSM) On-Prem Account Takeover (CVE-2024-20419)
CVE-2024-20419CRITICAL20 jul 2024
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
85RIESGO
abrir
Metasploit600
ProjectSend r1295 - r1605 Unauthenticated Remote Code Execution
CVE-2024-11680CRITICALbajo ataque19 jul 2024
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
Metasploit600
Geoserver unauthenticated Remote Code Execution
CVE-2024-36401CRITICALbajo ataque01 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
Metasploit600
Authenticated RCE in Splunk (splunk_archiver app)
CVE-2024-36985HIGH01 jul 2024
Remote Code Execution (RCE) through an external lookup due to “copybuckets.py“ script in the “splunk_archiver“ application in Splunk Enterprise
36RIESGO
abrir
Metasploit300
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
CVE-2024-5806CRITICAL25 jun 2024
MOVEit Transfer Authentication Bypass Vulnerability
85RIESGO
abrir
Metasploit300
Fortra FileCatalyst Workflow SQL Injection (CVE-2024-5276)
CVE-2024-5276CRITICAL25 jun 2024
SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
65RIESGO
abrir
Metasploit500
vCenter Sudo Privilege Escalation
CVE-2024-37081HIGH18 jun 2024
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An auth
36RIESGO
abrir
Metasploit600
Windows Access Mode Mismatch LPE in ks.sys
CVE-2024-35250HIGHbajo ataque11 jun 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.