Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
8176 exploits
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware20 ago 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-27925HIGHbajo ataqueransomware19 ago 2024
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-21587CRITICALbajo ataqueransomware19 ago 2024
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque18 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-38475CRITICALbajo ataque18 ago 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH18 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware17 ago 2024
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALbajo ataqueransomware16 ago 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL15 ago 2024
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
VulnCheck XDB
local
CVE-2024-30051HIGHbajo ataqueransomware14 ago 2024
Windows DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-22120CRITICAL14 ago 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALbajo ataque14 ago 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-22809HIGH14 ago 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-34102CRITICALbajo ataque13 ago 2024
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-22120CRITICAL13 ago 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL12 ago 2024
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-6308MEDIUM12 ago 2024
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque11 ago 2024
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-15368MEDIUM10 ago 2024
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL10 ago 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque10 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-6782CRITICAL09 ago 2024
Calibre Remote Code Execution
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware08 ago 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque08 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-3590MEDIUM08 ago 2024
WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALbajo ataque07 ago 2024
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque07 ago 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-6782CRITICAL06 ago 2024
Calibre Remote Code Execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque05 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-7339MEDIUM05 ago 2024
TVT DVR TD-2104TS-CL queryDevInfo information disclosure
60RIESGO
abrir
anteriorpágina 115 / 273siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.