Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
8176 exploits
VulnCheck XDB
initial-access
CVE-2023-47253CRITICAL19 sep 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-8752CRITICAL19 sep 2024
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-47253CRITICAL19 sep 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALbajo ataque18 sep 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALbajo ataque18 sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL17 sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2016-1092416 sep 2024
The ebook-download plugin before 1.2 for WordPress has directory traversal.
43RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-8190HIGHbajo ataque16 sep 2024
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-7965HIGHbajo ataque16 sep 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL16 sep 2024
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-44000CRITICAL16 sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-27564MEDIUM15 sep 2024
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-6782CRITICAL15 sep 2024
Calibre Remote Code Execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-40711CRITICALbajo ataqueransomware15 sep 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-1071CRITICAL15 sep 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-27950MEDIUMbajo ataque15 sep 2024
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL15 sep 2024
Code Injection in pyload/pyload
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALbajo ataque15 sep 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL14 sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALbajo ataque14 sep 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-8503CRITICAL14 sep 2024
VICIdial Unauthenticated SQL Injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALbajo ataque13 sep 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque13 sep 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3383113 sep 2024
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware12 sep 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware12 sep 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware10 sep 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL10 sep 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-0199HIGHbajo ataqueransomware10 sep 2024
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL09 sep 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir
anteriorpágina 112 / 273siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.