Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
macOS Dirty Cow Arbitrary File Write Local Privilege Escalation
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RIESGO
abrir ↗Metasploit600
Cacti 1.2.22 unauthenticated command injection
Unauthenticated Command Injection
100RIESGO
abrir ↗Metasploit300
Mirage firewall for QubesOS 0.8.0-0.8.3 Denial of Service (DoS) Exploit
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of s
61RIESGO
abrir ↗Metasploit0
WhatsUp Gold Credentials Dump
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke
18RIESGO
abrir ↗Metasploit0
WhatsUp Gold Credentials Dump
In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke
18RIESGO
abrir ↗Metasploit600
VSCode ipynb Remote Development RCE
Visual Studio Code Remote Code Execution Vulnerability
48RIESGO
abrir ↗Metasploit0
WhatsUp Gold Credentials Dump
In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to obt
18RIESGO
abrir ↗Metasploit0
WhatsUp Gold Credentials Dump
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to i
30RIESGO
abrir ↗Metasploit600
Bitbucket Environment Variable RCE
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker
65RIESGO
abrir ↗Metasploit600
F5 BIG-IP iControl Authenticated RCE via RPM Creator
Appliance mode iControl REST vulnerability
68RIESGO
abrir ↗Metasploit300
POWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121)
POWERCOM CO., LTD. UPSMON PRO - Path Traversal
28RIESGO
abrir ↗Metasploit300
POWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121)
POWERCOM CO., LTD. UPSMON PRO - Insufficiently Protected Credentials
28RIESGO
abrir ↗Metasploit400
Lenovo Diagnostics Driver IOCTL memmove
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RIESGO
abrir ↗Metasploit600
Acronis Cyber Protect/Backup remote code execution
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following
43RIESGO
abrir ↗Metasploit600
Authenticated RCE in Splunk (SimpleXML dashboard PDF generation)
Remote Code Execution through dashboard PDF generation component in Splunk Enterprise
41RIESGO
abrir ↗Metasploit600
Clinic's Patient Management System 1.0 - Unauthenticated RCE
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
68RIESGO
abrir ↗Metasploit600
VMware NSX Manager XStream unauthenticated RCE
XStream is vulnerable to a Remote Command Execution attack
100RIESGO
abrir ↗Metasploit600
SolarWinds Information Service (SWIS) .NET Deserialization From AMQP RCE
SolarWinds Platform Deserialization of Untrusted Data
48RIESGO
abrir ↗Metasploit600
Apache Commons Text RCE
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗Metasploit600
Zimbra sudo + postfix privilege escalation
Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalat
36RIESGO
abrir ↗Metasploit600
Fortinet FortiOS, FortiProxy, and FortiSwitchManager authentication bypass.
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir ↗Metasploit600
GitLab GitHub Repo Import Deserialization RCE
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows
85RIESGO
abrir ↗Metasploit600
Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RIESGO
abrir ↗Metasploit600
Microsoft Exchange ProxyNotShell RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit600
Microsoft Exchange ProxyNotShell RCE
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Metasploit600
mySCADA MyPRO Authenticated Command Injection (CVE-2023-28384)
CVE-2023-28384
48RIESGO
abrir ↗Metasploit300
Mobile Mouse RCE
RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).
63RIESGO
abrir ↗Metasploit300
Remote Control Collection RCE
Steppschuh Remote Control Server 3.1.1.12 Unauthenticated RCE
63RIESGO
abrir ↗Metasploit500
Ubuntu Enlightenment Mount Priv Esc
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.