Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Openfire authentication bypass with RCE plugin
Openfire administration console authentication bypass
100RIESGO
abrir ↗Metasploit300
GitLab Authenticated File Read
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir ↗Metasploit600
Apache RocketMQ update config RCE
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir ↗Metasploit600
Barracuda ESG TAR Filename Command Injection
Remote Code injection in Barracuda Email Security Gateway
100RIESGO
abrir ↗Metasploit600
SolarView Compact unauthenticated remote command execution vulnerability.
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir ↗Metasploit600
TOTOLINK Wireless Routers unauthenticated remote command execution vulnerability.
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/s
68RIESGO
abrir ↗Metasploit600
Sharepoint Dynamic Proxy Generator Unauth RCE
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Metasploit600
Sharepoint Dynamic Proxy Generator Unauth RCE
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit300
Apache Superset Signed Cookie Priv Esc
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗Metasploit600
Ivanti Avalanche FileStoreConfig File Upload
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could
58RIESGO
abrir ↗Metasploit300
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via t
36RIESGO
abrir ↗Metasploit600
ManageEngine ADManager Plus ChangePasswordAction Authenticated Command Injection
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy setti
58RIESGO
abrir ↗Metasploit300
CVE-2023-21554 - QueueJumper - MSMQ RCE Check
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RIESGO
abrir ↗Metasploit400
Windows Common Log File System Driver (clfs.sys) Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RIESGO
abrir ↗Metasploit300
Jasmin Ransomware Web Server Unauthenticated SQL Injection
codesiddhant Jasmin Ransomware checklogin.php sql injection
28RIESGO
abrir ↗Metasploit300
Jasmin Ransomware Web Server Unauthenticated Directory Traversal
Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive infor
28RIESGO
abrir ↗Metasploit300
ThinManager Path Traversal (CVE-2023-27856) Arbitrary File Download
Rockwell Automation ThinManager ThinServer Path Traversal Download
58RIESGO
abrir ↗Metasploit300
ThinManager Path Traversal (CVE-2023-27855) Arbitrary File Upload
Rockwell Automation ThinManager ThinServer Path Traversal Upload
48RIESGO
abrir ↗Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RIESGO
abrir ↗Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RIESGO
abrir ↗Metasploit500
Zyxel IKE Packet Decoder Unauthenticated Remote Code Execution
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir ↗Metasploit600
Nextcloud Workflows Remote Code Execution
Scope of workflow operations is not validated in nextcloud server
63RIESGO
abrir ↗Metasploit600
Rocket Software Unidata udadmin_server Authentication Bypass
Authentication bypass in UniRPC's udadmin service
75RIESGO
abrir ↗Metasploit400
Rocket Software Unidata udadmin_server Stack Buffer Overflow in Password
Stack buffer overflow in UniRPC's udadmin_server service
75RIESGO
abrir ↗Metasploit300
Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RIESGO
abrir ↗Metasploit600
Local Privilege Escalation via CVE-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗Metasploit300
MinIO Bootstrap Verify Information Disclosure
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗Metasploit600
pfSense Restore RRD Data Command Injection
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attac
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.