Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
ISPConfig language_edit.php PHP Code Injection
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by
41RIESGO
abrir ↗Metasploit600
Cisco IOX XE Unauthenticated RCE Chain
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗Metasploit600
Cisco IOX XE Unauthenticated RCE Chain
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RIESGO
abrir ↗Metasploit300
Cisco IOX XE unauthenticated OS command execution
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗Metasploit300
Cisco IOX XE unauthenticated OS command execution
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RIESGO
abrir ↗Metasploit300
Cisco IOX XE unauthenticated Command Line Interface (CLI) execution
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir ↗Metasploit600
Atlassian Confluence Unauthenticated Remote Code Execution
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗Metasploit300
Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗Metasploit600
PyTorch Model Server Registration and Deserialization RCE
TorchServe Server-Side Request Forgery
75RIESGO
abrir ↗Metasploit600
PyTorch Model Server Registration and Deserialization RCE
Remote Code execution in SnakeYAML
58RIESGO
abrir ↗Metasploit600
Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir ↗Metasploit600
Kafka UI Unauthenticated Remote Command Execution via the Groovy Filter option.
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the
78RIESGO
abrir ↗Metasploit600
Progress Software WS_FTP Unauthenticated Remote Code Execution
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RIESGO
abrir ↗Metasploit600
JetBrains TeamCity Unauthenticated Remote Code Execution
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗Metasploit600
Craft CMS unauthenticated Remote Code Execution (RCE)
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir ↗Metasploit600
Themebleed- Windows 11 Themes Arbitrary Code Execution CVE-2023-38146
Windows Themes Remote Code Execution Vulnerability
48RIESGO
abrir ↗Metasploit400
Apache Superset Signed Cookie RCE
Apache Superset: Metadata db write access can lead to remote code execution
53RIESGO
abrir ↗Metasploit400
Apache Superset Signed Cookie RCE
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗Metasploit400
Apache Superset Signed Cookie RCE
Apache Superset: Possible Unauthorized Registration of SQLite Database Connections
45RIESGO
abrir ↗Metasploit600
VMWare Aria Operations for Networks (vRealize Network Insight) SSH Private Key Exposure
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RIESGO
abrir ↗Metasploit600
LG Simple Editor Remote Code Execution
LG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability
65RIESGO
abrir ↗Metasploit600
WinRAR CVE-2023-38831 Exploit
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir ↗Metasploit600
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RIESGO
abrir ↗Metasploit300
ThinManager Path Traversal (CVE-2023-2917) Arbitrary File Upload
Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
65RIESGO
abrir ↗Metasploit600
Junos OS PHPRC Environment Variable Manipulation RCE
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir ↗Metasploit300
ThinManager Path Traversal (CVE-2023-2915) Arbitrary File Delete
Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
58RIESGO
abrir ↗Metasploit600
Ivanti Avalanche MDM Buffer Overflow
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RIESGO
abrir ↗Metasploit600
PRTG CVE-2023-32781 Authenticated RCE
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an au
23RIESGO
abrir ↗Metasploit600
CrushFTP Unauthenticated RCE
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes
60RIESGO
abrir ↗Metasploit600
LG Simple Editor Command Injection (CVE-2023-40504)
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability
65RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.