Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
DotCMS RCE via Arbitrary File Upload.
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req
100RIESGO
abrir ↗Metasploit600
Zyxel Firewall ZTP Unauthenticated Command Injection
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir ↗Metasploit600
ZoneMinder Language Settings Remote Code Execution
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an
30RIESGO
abrir ↗Metasploit300
VICIdial Multiple Authenticated SQLi
VICIDial 2.14b0.5 SVN 3550 was discovered to contain multiple SQL injection vulnerability at /vicidial/admin.php.
28RIESGO
abrir ↗Metasploit300
VICIdial Multiple Authenticated SQLi
VICIDial 2.14b0.5 SVN 3550 was discovered to contains a SQL injection vulnerability at /vicidial/AST_agent_time_sheet.php.
28RIESGO
abrir ↗Metasploit300
VICIdial Multiple Authenticated SQLi
VICIDial 2.14b0.5 SVN 3550 was discovered to contain a SQL injection vulnerability at /vicidial/user_stats.php.
28RIESGO
abrir ↗Metasploit300
VMware vCenter Secrets Dump
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RIESGO
abrir ↗Metasploit600
ManageEngine ADSelfService Plus Custom Script Execution
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary
100RIESGO
abrir ↗Metasploit600
VMware Workspace ONE Access CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗Metasploit400
VMware Workspace ONE Access CVE-2022-22960
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t
98RIESGO
abrir ↗Metasploit600
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities
23RIESGO
abrir ↗Metasploit600
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth
30RIESGO
abrir ↗Metasploit600
Dompdf RCE via Malicious Font Caching (CVE-2022-28368)
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RIESGO
abrir ↗Metasploit400
ALLMediaServer 1.6 SEH Buffer Overflow
Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrar
30RIESGO
abrir ↗Metasploit600
WSO2 Arbitrary File Upload to RCE
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir ↗Metasploit0
Spring Framework Class property RCE (Spring4Shell)
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗Metasploit600
Spring Cloud Function SpEL Injection
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir ↗Metasploit600
Wordpress Plugin Elementor Authenticated Upload Remote Code Execution
Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution
78RIESGO
abrir ↗Metasploit500
io_uring Same Type Object Reuse Priv Esc
A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to cor
18RIESGO
abrir ↗Metasploit600
Open Web Analytics 1.7.3 - Remote Code Execution (RCE)
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir ↗Metasploit600
User Profile Arbitrary Junction Creation Local Privilege Elevation
Windows User Profile Service Elevation of Privilege Vulnerability
66RIESGO
abrir ↗Metasploit500
Watch Queue Out of Bounds Write
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This
38RIESGO
abrir ↗Metasploit300
WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
60RIESGO
abrir ↗Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskst
30RIESGO
abrir ↗Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RIESGO
abrir ↗Metasploit300
Wordpress BookingPress bookingpress_front_get_category_services SQLi
BookingPress < 1.0.11 - Unauthenticated SQL Injection
30RIESGO
abrir ↗Metasploit600
Webmin File Manager RCE
Improper Access Control to Remote Code Execution in webmin/webmin
78RIESGO
abrir ↗Metasploit300
GitLab GraphQL API User Enumeration
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv
70RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.