Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
WordPress Plugin Automatic Config Change to RCE
WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update
48RIESGO
abrir ↗Metasploit600
Atlassian Confluence WebWork OGNL Injection
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗Metasploit300
Canon Driver Privilege Escalation
The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer pro
18RIESGO
abrir ↗Metasploit300
Pi-Hole Top Domains API Authenticated Exec
(Authenticated) Remote Code Execution Possible in Web Interface 5.5
48RIESGO
abrir ↗Metasploit600
ManageEngine OpManager SumPDU Java Deserialization
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the
30RIESGO
abrir ↗Metasploit600
ManageEngine OpManager SumPDU Java Deserialization
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RIESGO
abrir ↗Metasploit300
Elasticsearch Memory Disclosure
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
60RIESGO
abrir ↗Metasploit300
Windows SAM secrets leak - HiveNightmare
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir ↗Metasploit600
Nagios XI Autodiscovery Webshell Upload
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post au
23RIESGO
abrir ↗Metasploit300
Jetty WEB-INF File Disclosure
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RIESGO
abrir ↗Metasploit300
Lexmark Driver Privilege Escalation
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below,
18RIESGO
abrir ↗Metasploit300
Jetty WEB-INF File Disclosure
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RIESGO
abrir ↗Metasploit600
Geutebruck Multiple Remote Command Execution
UDP Technology/Geutebrück camera devices: Authentication Bypass
65RIESGO
abrir ↗Metasploit600
Geutebruck instantrec Remote Command Execution
UDP Technology/Geutebrück camera devices: Buffer overflow in action parameter leading to RCE
48RIESGO
abrir ↗Metasploit600
Geutebruck Multiple Remote Command Execution
UDP Technology/Geutebrück camera devices: Command injection in preserve parameter leading to RCE
48RIESGO
abrir ↗Metasploit600
Geutebruck Multiple Remote Command Execution
UDP Technology/Geutebrück camera devices: Command injection in command parameter leading to RCE
48RIESGO
abrir ↗Metasploit600
Geutebruck Multiple Remote Command Execution
UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
48RIESGO
abrir ↗Metasploit600
Geutebruck Multiple Remote Command Execution
UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
48RIESGO
abrir ↗Metasploit600
Geutebruck Multiple Remote Command Execution
UDP Technology/Geutebrück camera devices: Command injection in appfile.filename parameter leading to RCE
48RIESGO
abrir ↗Metasploit600
Geutebruck Multiple Remote Command Execution
UDP Technology/Geutebrück camera devices: Command injection in environment.lang parameter leading to RCE
48RIESGO
abrir ↗Metasploit600
Geutebruck Multiple Remote Command Execution
UDP Technology/Geutebrück camera devices: command injection leading to RCE
58RIESGO
abrir ↗Metasploit500
Netfilter x_tables Heap OOB Write Privilege Escalation
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir ↗Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
Sage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actor
40RIESGO
abrir ↗Metasploit400
Sage X3 Administration Service Authentication Bypass Command Execution
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
75RIESGO
abrir ↗Metasploit600
ForgeRock / OpenAM Jato Java Deserialization
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir ↗Metasploit600
Moodle SpellChecker Path Authenticated Remote Command Execution
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted s
41RIESGO
abrir ↗Metasploit600
Wordpress Plugin SP Project and Document - Authenticated Remote Code Execution
SP Project & Document Manager <2 4.22 - Authenticated Shell Upload
30RIESGO
abrir ↗Metasploit600
elFinder Archive Command Injection
Multiple vulnerabilities leading to RCE
75RIESGO
abrir ↗Metasploit300
Wordpress Popular Posts Authenticated RCE
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RIESGO
abrir ↗Metasploit300
Print Spooler Remote DLL Injection
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.