Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
Log4Shell HTTP Scanner
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Metasploit600
Log4Shell HTTP Header Injection
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Metasploit600
VMware vCenter Server Unauthenticated JNDI Injection RCE (via Log4Shell)
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Metasploit600
AjaxPro Deserialization Remote Code Execution
Deserialization of Untrusted Data
58RIESGO
abrir ↗Metasploit600
Ivanti Cloud Services Appliance (CSA) Command Injection
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RIESGO
abrir ↗Metasploit300
Wordpress Secure Copy Content Protection and Content Locking sccp_id Unauthenticated SQLi
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RIESGO
abrir ↗Metasploit600
Sitecore Experience Platform (XP) PreAuth Deserialization RCE
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RIESGO
abrir ↗Metasploit600
Cisco RV Series Authentication Bypass and Command Injection
Cisco Small Business RV Series Routers Vulnerabilities
85RIESGO
abrir ↗Metasploit600
Cisco RV Series Authentication Bypass and Command Injection
Cisco Small Business RV Series Routers Vulnerabilities
85RIESGO
abrir ↗Metasploit300
ChurchInfo 1.2.13-1.3.0 Authenticated RCE
CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requir
41RIESGO
abrir ↗Metasploit300
WordPress WPS Hide Login Login Page Revealer
WPS Hide Login < 1.9.1 - Protection Bypass with Referer-Header
40RIESGO
abrir ↗Metasploit600
Zimbra zmslapd arbitrary module load
Zimbra zmslapd arbitrary module load
18RIESGO
abrir ↗Metasploit600
Apache Storm Nimbus getTopologyHistory Unauthenticated Command Execution
Shell Command Injection Vulnerability in Nimbus Thrift Server
40RIESGO
abrir ↗Metasploit300
BillQuick Web Suite txtID SQLi
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution
95RIESGO
abrir ↗Metasploit300
Wordpress Plugin Catch Themes Demo Import RCE
Catch Themes Demo Import <= 1.7 Admin+ Arbitrary File Upload
48RIESGO
abrir ↗Metasploit400
Win32k NtGdiResetDC Use After Free Local Privilege Elevation
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Metasploit600
WordPress Plugin Pie Register Auth Bypass to RCE
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir ↗Metasploit300
WordPress Plugin Perfect Survey 1.5.1 SQLi (Unauthenticated)
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RIESGO
abrir ↗Metasploit600
ManageEngine ADAudit Plus Authenticated File Write RCE
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
40RIESGO
abrir ↗Metasploit600
Microsoft Office Word Malicious MSHTML RCE
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit600
VMware vCenter Server Analytics (CEIP) Service File Upload
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir ↗Metasploit0
VMware vCenter vScalation Priv Esc
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and
18RIESGO
abrir ↗Metasploit600
Hikvision IP Camera Unauthenticated Command Injection
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗Metasploit300
Wordpress BulletProof Security Backup Disclosure
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RIESGO
abrir ↗Metasploit600
ManageEngine ServiceDesk Plus CVE-2021-44077
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RIESGO
abrir ↗Metasploit600
Microsoft OMI Management Interface Authentication Bypass
Open Management Infrastructure Elevation of Privilege Vulnerability
91RIESGO
abrir ↗Metasploit600
Microsoft OMI Management Interface Authentication Bypass
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit600
ManageEngine ADSelfService Plus CVE-2021-40539
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RIESGO
abrir ↗Metasploit300
Netgear PNPX_GetShareFolderList Authentication Bypass
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.