Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗Metasploit300
Wordpress POST SMTP Account Takeover
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir ↗Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗Metasploit600
Barracuda ESG Spreadsheet::ParseExcel Arbitrary Code Execution
Arbitrary Code Execution (ACE) Vulnerability
71RIESGO
abrir ↗Metasploit600
Barracuda ESG Spreadsheet::ParseExcel Arbitrary Code Execution
Remote Code Execution (RCE) Vulnerability
30RIESGO
abrir ↗Metasploit600
MajorDoMo Command Injection
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RIESGO
abrir ↗Metasploit600
WordPress Backup Migration Plugin PHP Filter Chain RCE
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir ↗Metasploit600
GL.iNet Unauthenticated Remote Command Execution via the logread module.
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000
36RIESGO
abrir ↗Metasploit600
GL.iNet Unauthenticated Remote Command Execution via the logread module.
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string
75RIESGO
abrir ↗Metasploit600
Chamilo v1.11.24 Unrestricted File Upload PHP Webshell
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗Metasploit600
Splunk Authenticated XSLT Upload RCE
Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
58RIESGO
abrir ↗Metasploit300
Control iD iDSecure Authentication Bypass (CVE-2023-6329)
Control iD iDSecure passwordCustom Authentication Bypass
75RIESGO
abrir ↗Metasploit600
WordPress Royal Elementor Addons RCE
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗Metasploit300
ownCloud Phpinfo Reader
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RIESGO
abrir ↗Metasploit600
Ray cpu_profile command injection
Ray Command Injection in cpu_profile Parameter
85RIESGO
abrir ↗Metasploit600
Ray Agent Job RCE
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RIESGO
abrir ↗Metasploit600
GitLens Git Local Configuration Exec
An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Vis
18RIESGO
abrir ↗Metasploit300
WordPress WP Fastest Cache Unauthenticated SQLi (CVE-2023-6063)
WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection
40RIESGO
abrir ↗Metasploit600
WonderCMS Remote Code Execution
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir ↗Metasploit600
Atlassian Confluence Unauth JSON setup-restore Improper Authorization leading to RCE (CVE-2023-22518)
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir ↗Metasploit600
Apache ActiveMQ Unauthenticated Remote Code Execution
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗Metasploit600
F5 BIG-IP TMUI AJP Smuggling RCE
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir ↗Metasploit600
Vinchin Backup and Recovery Command Injection
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability
68RIESGO
abrir ↗Metasploit600
Vinchin Backup and Recovery Command Injection
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
18RIESGO
abrir ↗Metasploit300
Citrix ADC (NetScaler) Bleed Scanner
Unauthenticated sensitive information disclosure
100RIESGO
abrir ↗Metasploit600
Mirth Connect Deserialization RCE
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir ↗Metasploit600
Mirth Connect Deserialization RCE
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary com
40RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.