Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
8176 exploits
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware11 nov 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH10 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10586CRITICAL10 nov 2024
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL10 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL09 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM09 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2083709 nov 2024
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21626HIGH07 nov 2024
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-6553CRITICAL07 nov 2024
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-51567CRITICALbajo ataqueransomware07 nov 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-23334MEDIUM07 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALbajo ataque07 nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware06 nov 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-2907805 nov 2024
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-50498CRITICAL04 nov 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-37383MEDIUMbajo ataque03 nov 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH02 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
client-side
CVE-2015-925101 nov 2024
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-1071CRITICAL01 nov 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-51567CRITICALbajo ataqueransomware31 oct 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-3129CRITICALbajo ataqueransomware31 oct 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23113CRITICALbajo ataque31 oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-27954CRITICAL30 oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27954CRITICAL29 oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-51378CRITICALbajo ataqueransomware29 oct 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-44258HIGH29 oct 2024
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18
41RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware28 oct 2024
Information disclosure
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH27 oct 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
local
CVE-2024-35250HIGHbajo ataque25 oct 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-23131CRITICALbajo ataque25 oct 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
anteriorpágina 108 / 273siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.