Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.064 exploits
Exploit-DB✓ VexDay Proof
OpenMediaVault Cron - Remote Command Execution (Metasploit)
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users
68RIESGO
abrir ↗Metasploit600
Apache Roller OGNL Injection
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ISPConfig - (Authenticated) Arbitrary PHP Code Execution (Metasploit)
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
50RIESGO
abrir ↗Metasploit600
Synology DiskStation Manager SLICEUPLOAD Remote Command Execution
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zabbix - (Authenticated) Remote Command Execution (Metasploit)
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Moodle - Remote Command Execution (Metasploit)
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vTiger CRM 5.3.0 5.4.0 - (Authenticated) Remote Code Execution (Metasploit)
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NAS4Free - Remote Code Execution (Metasploit)
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.p
43RIESGO
abrir ↗Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir ↗Exploit-DB
Opsview pre 4.4.1 - Blind SQL Injection
SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir ↗Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir ↗Metasploit600
HP LoadRunner EmulationAdmin Web Service Directory Traversal
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb
50RIESGO
abrir ↗Metasploit500
Rocket Servergraph Admin Center fileRequestor Remote Code Execution
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows
60RIESGO
abrir ↗Metasploit600
vTigerCRM v5.4.0/v5.3.0 Authenticated Remote Code Execution
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
50RIESGO
abrir ↗Metasploit600
OpenMediaVault rpc.php Authenticated Cron Remote Code Execution
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users
68RIESGO
abrir ↗Metasploit600
ISPConfig Authenticated Arbitrary PHP Code Execution
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
50RIESGO
abrir ↗Metasploit500
HP SiteScope issueSiebelCmd Remote Code Execution
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authenti
60RIESGO
abrir ↗Metasploit500
NAS4Free Arbitrary Remote Code Execution
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.p
43RIESGO
abrir ↗Metasploit300
Openbravo ERP XXE Arbitrary File Read
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML
43RIESGO
abrir ↗Metasploit600
Moodle Authenticated Spelling Binary RCE
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, an
43RIESGO
abrir ↗Metasploit600
Zabbix Authenticated Remote Command Execution
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RIESGO
abrir ↗Metasploit600
Moodle Authenticated Spelling Binary RCE
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Openbravo ERP - XML External Entity Information Disclosure
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir ↗Exploit-DB
Watchguard Firewall XTM 11.7.4u1 - Remote Buffer Overflow
Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code
28RIESGO
abrir ↗Exploit-DB
Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (1)
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
23RIESGO
abrir ↗Exploit-DB
Stem Innovation - 'IZON' Hard-Coded Credentials
IZON IP 2.0.2: hard-coded password vulnerability
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.