Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Adobe ColdFusion Unauthenticated Remote Code Execution
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir ↗Metasploit300
Dolibarr 16 pre-auth contact database dump
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's
23RIESGO
abrir ↗Metasploit600
Lexmark Device Embedded Web Server RCE
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
68RIESGO
abrir ↗Metasploit600
PaperCut PaperCutNG Authentication Bypass
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗Metasploit300
Pretalx Arbitrary File Read/Limited File Write
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload craft
28RIESGO
abrir ↗Metasploit300
Pretalx Arbitrary File Read/Limited File Write
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RIESGO
abrir ↗Metasploit600
Pretalx Limited File Write to Remote Code Execution
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RIESGO
abrir ↗Metasploit600
SPIP form PHP Injection
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗Metasploit600
ZoneMinder Snapshots Command Injection
ZoneMinder vulnerable to Missing Authorization
58RIESGO
abrir ↗Metasploit300
RPyC 4.1.0 through 4.1.1 Remote Command Execution
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure
23RIESGO
abrir ↗Metasploit600
Fortinet FortiNAC keyUpload.jsp arbitrary file write
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RIESGO
abrir ↗Metasploit600
Lucee Authenticated Scheduled Job Code Execution
Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
63RIESGO
abrir ↗Metasploit600
Apache Druid JNDI Injection RCE
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RIESGO
abrir ↗Metasploit300
Joomla API Improper Access Checks
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗Metasploit600
Fortra GoAnywhere MFT Unsafe Deserialization RCE
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RIESGO
abrir ↗Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi
85RIESGO
abrir ↗Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sen
53RIESGO
abrir ↗Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
85RIESGO
abrir ↗Metasploit600
Sudoedit Extra Arguments Priv Esc
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗Metasploit600
Oracle Weblogic PreAuth Remote Command Execution via ForeignOpaqueReference IIOP Deserialization
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir ↗Metasploit300
Wordpress Paid Membership Pro code Unauthenticated SQLi
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir ↗Metasploit600
Ancillary Function Driver (AFD) for WinSock Elevation of Privilege
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RIESGO
abrir ↗Metasploit600
ManageEngine ADSelfService Plus Unauthenticated SAML RCE
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir ↗Metasploit600
ManageEngine ServiceDesk Plus Unauthenticated SAML RCE
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir ↗Metasploit600
ManageEngine Endpoint Central Unauthenticated SAML RCE
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir ↗Metasploit600
Jorani unauthenticated Remote Code Execution
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
60RIESGO
abrir ↗Metasploit600
CWP login.php Unauthenticated RCE
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RIESGO
abrir ↗Metasploit400
SugarCRM unauthenticated Remote Code Execution (RCE)
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because o
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.