Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
Magento XXE Unserialize Arbitrary File Read
CVE-2024-34102CRITICALbajo ataque11 jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
Metasploit600
Windows Kernel Time of Check Time of Use LPE in AuthzBasepCopyoutInternalSecurityAttributes
CVE-2024-30038HIGH11 jun 2024
Win32k Elevation of Privilege Vulnerability
36RIESGO
abrir
Metasploit600
PHP CGI Argument Injection Remote Code Execution
CVE-2024-4577CRITICALbajo ataqueransomware06 jun 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
Metasploit600
Telerik Report Server Auth Bypass and Deserialization RCE
CVE-2024-1800CRITICAL04 jun 2024
Progress Telerik Report Server Deserialization
55RIESGO
abrir
Metasploit300
Telerik Report Server Auth Bypass
CVE-2024-4358CRITICALbajo ataque04 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
Metasploit600
Telerik Report Server Auth Bypass and Deserialization RCE
CVE-2024-4358CRITICALbajo ataque04 jun 2024
Registration Authentication Bypass Vulnerability
100RIESGO
abrir
Metasploit0
macOS PackageKit ZSH Environment Privilege Escalation
CVE-2024-27822HIGH03 jun 2024
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to
36RIESGO
abrir
Metasploit600
Apache OFBiz forgotPassword/ProgramExport RCE
CVE-2024-32113CRITICALbajo ataque30 may 2024
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
Metasploit600
Apache OFBiz forgotPassword/ProgramExport RCE
CVE-2024-38856HIGHbajo ataque30 may 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
Metasploit600
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution
CVE-2024-23692CRITICALbajo ataqueransomware25 may 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
Metasploit300
Ivanti EPM RecordGoodApp SQLi RCE
CVE-2024-29824CRITICALbajo ataque24 may 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RIESGO
abrir
Metasploit600
WordPress Hash Form Plugin RCE
CVE-2024-5084CRITICAL23 may 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RIESGO
abrir
Metasploit600
Atlassian Confluence Administrator Code Macro Remote Code Execution
CVE-2024-21683HIGH21 may 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RIESGO
abrir
Metasploit600
Cacti Import Packages RCE
CVE-2024-25641CRITICAL12 may 2024
Cacti RCE vulnerability when importing packages
85RIESGO
abrir
Metasploit600
DIAEnergie SQL Injection (CVE-2024-4548)
CVE-2024-4548CRITICAL06 may 2024
Delta Electronics DIAEnergie SQL Injection
48RIESGO
abrir
Metasploit600
Ollama Model Registry Path Traversal RCE
CVE-2024-37032HIGH05 may 2024
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,
78RIESGO
abrir
Metasploit600
Flowmon Unauthenticated Command Injection
CVE-2024-2389CRITICAL23 abr 2024
Flowmon Unauthenticated Command Injection Vulnerability
85RIESGO
abrir
Metasploit600
Apache HugeGraph Gremlin RCE
CVE-2024-27348CRITICALbajo ataque22 abr 2024
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
Metasploit600
FortiNet FortiClient Endpoint Management Server FCTID SQLi to RCE
CVE-2023-48788CRITICALbajo ataqueransomware21 abr 2024
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio
100RIESGO
abrir
Metasploit600
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
CVE-2024-3400CRITICALbajo ataqueransomware12 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
Metasploit300
Netdata ndsudo privilege escalation
CVE-2024-32019HIGH12 abr 2024
ndsudo: local privilege escalation via untrusted search path
36RIESGO
abrir
Metasploit600
Chaos RAT XSS to RCE
CVE-2024-31839MEDIUM10 abr 2024
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via th
28RIESGO
abrir
Metasploit600
Chaos RAT XSS to RCE
CVE-2024-3085010 abr 2024
15RIESGO
abrir
Metasploit600
AVideo WWBNIndex Plugin Unauthenticated RCE
CVE-2024-31819CRITICAL09 abr 2024
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath
68RIESGO
abrir
Metasploit600
pgAdmin Binary Path API RCE
CVE-2024-3116HIGH28 mar 2024
Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4
48RIESGO
abrir
Metasploit600
Kemp LoadMaster Unauthenticated Command Injection
CVE-2024-1212CRITICALbajo ataque19 mar 2024
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir
Metasploit600
Progress Flowmon Local sudo privilege escalation
CVE-2024-2389CRITICAL19 mar 2024
Flowmon Unauthenticated Command Injection Vulnerability
85RIESGO
abrir
Metasploit600
Kemp LoadMaster Local sudo privilege escalation
CVE-2024-1212CRITICALbajo ataque19 mar 2024
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir
Metasploit600
Gibbon School Platform Authenticated PHP Deserialization Vulnerability
CVE-2024-24725HIGH18 mar 2024
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POS
48RIESGO
abrir
Metasploit600
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
CVE-2024-24578CRITICAL16 mar 2024
RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
43RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.