Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Eramba (up to 3.19.1) Authenticated Remote Code Execution Module
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrar
30RIESGO
abrir ↗Metasploit600
Maltrail Unauthenticated Command Injection
stamparm/maltrail <=0.54 Remote Command Execution
63RIESGO
abrir ↗Metasploit600
RaspAP Unauthenticated Command Injection
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary comma
60RIESGO
abrir ↗Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RIESGO
abrir ↗Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RIESGO
abrir ↗Metasploit600
Greenshot .NET Deserialization Fileformat Exploit
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green
38RIESGO
abrir ↗Metasploit600
Metabase Setup Token RCE
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir ↗Metasploit300
Citrix ADC (NetScaler) Forms SSO Target RCE
Unauthenticated remote code execution
100RIESGO
abrir ↗Metasploit600
BoidCMS Command Injection
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header t
60RIESGO
abrir ↗Metasploit600
Sonicwall
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GM
58RIESGO
abrir ↗Metasploit600
Sonicwall
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and
58RIESGO
abrir ↗Metasploit600
Sonicwall
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
75RIESGO
abrir ↗Metasploit600
Sonicwall
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the
18RIESGO
abrir ↗Metasploit600
Microsoft Error Reporting Local Privilege Elevation Vulnerability
Windows Error Reporting Service Elevation of Privilege Vulnerability
98RIESGO
abrir ↗Metasploit600
OpenNMS Horizon Authenticated RCE
ROLE_REST can be used to escalate to ROLE_ADMIN via /rest/users
36RIESGO
abrir ↗Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
Remote Code Execution in OpenTSDB
75RIESGO
abrir ↗Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
Remote Code Execution in OpenTSDB
68RIESGO
abrir ↗Metasploit600
OpenNMS Horizon Authenticated RCE
ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN
28RIESGO
abrir ↗Metasploit600
MagnusBilling application unauthenticated Remote Command Execution.
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir ↗Metasploit600
Rudder Server SQLI Remote Code Execution
rudder-server vulnerable to SQL Injection
58RIESGO
abrir ↗Metasploit600
Apache NiFi H2 Connection String Remote Code Execution
Apache NiFi: Potential Code Injection with Database Services using H2
48RIESGO
abrir ↗Metasploit300
MongoDB Ops Manager Diagnostic Archive Sensitive Information Retriever
MongoDB Ops Manager may disclose sensitive information in Diagnostic Archive
23RIESGO
abrir ↗Metasploit600
Ivanti EPM Agent Portal Command Execution
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege es
41RIESGO
abrir ↗Metasploit600
VMWare Aria Operations for Networks (vRealize Network Insight) pre-authenticated RCE
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RIESGO
abrir ↗Metasploit600
CmsMadeSimple Authenticated File Manager RCE
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
30RIESGO
abrir ↗Metasploit600
Splunk "edit_user" Capability Privilege Escalation
‘edit_user’ Capability Privilege Escalation
78RIESGO
abrir ↗Metasploit600
Chamilo unauthenticated command injection in PowerPoint upload
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RIESGO
abrir ↗Metasploit600
MOVEit SQL Injection vulnerability
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗Metasploit600
Wordpress File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution through shortcode
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RIESGO
abrir ↗Metasploit600
Dolibarr ERP/CRM Authenticated Code Injection
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instea
58RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.