Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
Syncovery For Linux Web-GUI Session Token Brute-Forcer
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and be
18RIESGO
abrir ↗Metasploit600
Syncovery For Linux Web-GUI Authenticated Remote Command Execution
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote c
30RIESGO
abrir ↗Metasploit500
pfSense plugin pfBlockerNG unauthenticated RCE as root
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir ↗Metasploit600
Symmetricom SyncServer Unauthenticated Remote Command Execution
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
85RIESGO
abrir ↗Metasploit400
WatchGuard XTM Firebox Unauthenticated Remote Command Execution
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RIESGO
abrir ↗Metasploit600
Bitbucket Git Command Injection
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir ↗Metasploit600
FLIR AX8 unauthenticated RCE
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RIESGO
abrir ↗Metasploit300
Rancher Authenticated API Credential Exposure
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
63RIESGO
abrir ↗Metasploit500
VMware Workspace ONE Access CVE-2022-31660
VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A m
18RIESGO
abrir ↗Metasploit600
Softing Secure Integration Server v1.22 Remote Code Execution
Softing Secure Integration Server Relative Path Traversal
41RIESGO
abrir ↗Metasploit600
Softing Secure Integration Server v1.22 Remote Code Execution
Softing Secure Integration Server Uncontrolled Search Path Element
41RIESGO
abrir ↗Metasploit600
Webmin Package Updates RCE
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RIESGO
abrir ↗Metasploit600
Apache Spark Unauthenticated Command Injection RCE
Apache Spark shell command injection vulnerability via Spark UI
100RIESGO
abrir ↗Metasploit600
Roxy-WI Prior to 6.1.1.0 Unauthenticated Command Injection RCE
Unauthenticated Remote Code Execution in Roxy-WI
85RIESGO
abrir ↗Metasploit600
ManageEngine ADAudit Plus CVE-2022-28219
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote
60RIESGO
abrir ↗Metasploit600
TAR Path Traversal in Zimbra (CVE-2022-41352)
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RIESGO
abrir ↗Metasploit600
UnRAR Path Traversal in Zimbra (CVE-2022-30333)
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RIESGO
abrir ↗Metasploit600
UnRAR Path Traversal (CVE-2022-30333)
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RIESGO
abrir ↗Metasploit600
Zoho Password Manager Pro XML-RPC Java Deserialization
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code
100RIESGO
abrir ↗Metasploit600
Cisco ASA-X with FirePOWER Services Authenticated Command Injection
Cisco FirePOWER Software for ASA FirePOWER Module Command Injection Vulnerability
40RIESGO
abrir ↗Metasploit600
Zyxel Firewall SUID Binary Privilege Escalation
A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 t
36RIESGO
abrir ↗Metasploit600
Atlassian Confluence Namespace OGNL Injection
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗Metasploit600
Microsoft Office Word MSDTJS
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit300
SuiteCRM authenticated SQL injection in export functionality
SQL Injection in salesagility/suitecrm
28RIESGO
abrir ↗Metasploit600
Gitea Git Fetch Remote Code Execution
Gitea before 1.16.7 does not escape git fetch remote.
60RIESGO
abrir ↗Metasploit600
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RIESGO
abrir ↗Metasploit600
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir ↗Metasploit300
Icingaweb Directory Traversal in Static Library File Requests
Path traversal in Icinga Web 2
78RIESGO
abrir ↗Metasploit600
F5 BIG-IP iControl RCE via REST Authentication Bypass
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.