Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
8176 exploits
VulnCheck XDB
infoleak
CVE-2024-0012CRITICALbajo ataqueransomware19 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware19 nov 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-9593HIGH18 nov 2024
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL18 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-3806CRITICAL18 nov 2024
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-1698CRITICAL16 nov 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL16 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-8856CRITICAL16 nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALbajo ataque15 nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-52301HIGH15 nov 2024
Laravel allows environment manipulation via query string
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL15 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL15 nov 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL15 nov 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-3495CRITICAL15 nov 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL14 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM14 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27997CRITICALbajo ataqueransomware14 nov 2024
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-1653HIGHbajo ataque14 nov 2024
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-8069MEDIUMbajo ataque13 nov 2024
Limited remote code execution with privilege of a NetworkService Account access
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL13 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH13 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-8963CRITICALbajo ataque13 nov 2024
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2013-015613 nov 2024
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque13 nov 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALbajo ataqueransomware12 nov 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
VulnCheck XDB
local
CVE-2015-132812 nov 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-21661HIGH12 nov 2024
SQL injection in WordPress
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque12 nov 2024
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware11 nov 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware11 nov 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
anteriorpágina 107 / 273siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.