Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
Log4Shell HTTP Scanner
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit600
Log4Shell HTTP Header Injection
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit600
VMware vCenter Server Unauthenticated JNDI Injection RCE (via Log4Shell)
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit600
AjaxPro Deserialization Remote Code Execution
CVE-2021-23758HIGH03 dic 2021
Deserialization of Untrusted Data
58RIESGO
abrir
Metasploit600
Ivanti Cloud Services Appliance (CSA) Command Injection
CVE-2021-44529CRITICALbajo ataqueransomware02 dic 2021
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RIESGO
abrir
Metasploit300
Grafana Plugin Path Traversal
CVE-2021-43798HIGHbajo ataque02 dic 2021
Grafana path traversal
100RIESGO
abrir
Metasploit300
Wordpress Secure Copy Content Protection and Content Locking sccp_id Unauthenticated SQLi
CVE-2021-2493108 nov 2021
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RIESGO
abrir
Metasploit600
Sitecore Experience Platform (XP) PreAuth Deserialization RCE
CVE-2021-42237CRITICALbajo ataqueransomware02 nov 2021
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RIESGO
abrir
Metasploit600
Cisco RV Series Authentication Bypass and Command Injection
CVE-2022-20707CRITICAL02 nov 2021
Cisco Small Business RV Series Routers Vulnerabilities
85RIESGO
abrir
Metasploit600
Cisco RV Series Authentication Bypass and Command Injection
CVE-2022-20705CRITICAL02 nov 2021
Cisco Small Business RV Series Routers Vulnerabilities
85RIESGO
abrir
Metasploit300
ChurchInfo 1.2.13-1.3.0 Authenticated RCE
CVE-2021-43258HIGH30 oct 2021
CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requir
41RIESGO
abrir
Metasploit300
WordPress WPS Hide Login Login Page Revealer
CVE-2021-2491727 oct 2021
WPS Hide Login < 1.9.1 - Protection Bypass with Referer-Header
40RIESGO
abrir
Metasploit600
Zimbra zmslapd arbitrary module load
CVE-2022-3739327 oct 2021
Zimbra zmslapd arbitrary module load
18RIESGO
abrir
Metasploit600
Apache Storm Nimbus getTopologyHistory Unauthenticated Command Execution
CVE-2021-3829425 oct 2021
Shell Command Injection Vulnerability in Nimbus Thrift Server
40RIESGO
abrir
Metasploit300
BillQuick Web Suite txtID SQLi
CVE-2021-42258CRITICALbajo ataqueransomware22 oct 2021
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution
95RIESGO
abrir
Metasploit300
Wordpress Plugin Catch Themes Demo Import RCE
CVE-2021-39352HIGH21 oct 2021
Catch Themes Demo Import <= 1.7 Admin+ Arbitrary File Upload
48RIESGO
abrir
Metasploit400
Win32k NtGdiResetDC Use After Free Local Privilege Elevation
CVE-2021-40449HIGHbajo ataqueransomware12 oct 2021
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
WordPress Plugin Pie Register Auth Bypass to RCE
CVE-2025-34077CRITICAL08 oct 2021
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir
Metasploit300
WordPress Plugin Perfect Survey 1.5.1 SQLi (Unauthenticated)
CVE-2021-2476205 oct 2021
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RIESGO
abrir
Metasploit600
ManageEngine ADAudit Plus Authenticated File Write RCE
CVE-2021-4284701 oct 2021
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
40RIESGO
abrir
Metasploit600
Microsoft Office Word Malicious MSHTML RCE
CVE-2021-40444HIGHbajo ataqueransomware23 sep 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
VMware vCenter Server Analytics (CEIP) Service File Upload
CVE-2021-22005CRITICALbajo ataqueransomware21 sep 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
Metasploit0
VMware vCenter vScalation Priv Esc
CVE-2021-2201521 sep 2021
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and
18RIESGO
abrir
Metasploit600
Hikvision IP Camera Unauthenticated Command Injection
CVE-2021-36260CRITICALbajo ataque18 sep 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
Metasploit300
Wordpress BulletProof Security Backup Disclosure
CVE-2021-39327MEDIUM17 sep 2021
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RIESGO
abrir
Metasploit600
ManageEngine ServiceDesk Plus CVE-2021-44077
CVE-2021-44077CRITICALbajo ataque16 sep 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RIESGO
abrir
Metasploit600
Microsoft OMI Management Interface Authentication Bypass
CVE-2021-38648HIGHbajo ataque14 sep 2021
Open Management Infrastructure Elevation of Privilege Vulnerability
91RIESGO
abrir
Metasploit600
Microsoft OMI Management Interface Authentication Bypass
CVE-2021-38647CRITICALbajo ataqueransomware14 sep 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
ManageEngine ADSelfService Plus CVE-2021-40539
CVE-2021-40539CRITICALbajo ataqueransomware07 sep 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RIESGO
abrir
Metasploit300
Netgear PNPX_GetShareFolderList Authentication Bypass
CVE-2021-45511MEDIUM06 sep 2021
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021
33RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.