Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
8195 exploits
VulnCheck XDB
local
CVE-2020-0041HIGHbajo ataque14 ago 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware14 ago 2023
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM13 ago 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque13 ago 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34621CRITICAL12 ago 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware11 ago 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALbajo ataque11 ago 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-38408CRITICAL09 ago 2023
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4542MEDIUM09 ago 2023
D-Link DAR-8000-10 sys1.php os command injection
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34621CRITICAL09 ago 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-2503209 ago 2023
PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
38RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864609 ago 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM09 ago 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864609 ago 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-095207 ago 2023
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-26067HIGH07 ago 2023
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware06 ago 2023
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALbajo ataqueransomware06 ago 2023
Unauthenticated remote code execution
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-22809HIGH06 ago 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALbajo ataqueransomware05 ago 2023
Unauthenticated remote code execution
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM05 ago 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-1135805 ago 2023
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-6789CRITICALbajo ataqueransomware05 ago 2023
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2013-382705 ago 2023
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-2732CRITICAL05 ago 2023
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
VulnCheck XDB
local
CVE-2021-22555HIGHbajo ataque05 ago 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-35082CRITICALbajo ataqueransomware04 ago 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864603 ago 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALbajo ataqueransomware02 ago 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864602 ago 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
anteriorpágina 155 / 274siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.