Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit500
2021 Ubuntu Overlayfs LPE
CVE-2021-3493HIGHbajo ataque12 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
CVE-2021-1473MEDIUM07 abr 2021
Cisco Small Business RV Series Routers Vulnerabilities
40RIESGO
abrir
Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
CVE-2021-1472MEDIUM07 abr 2021
Cisco Small Business RV Series Routers Vulnerabilities
50RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyShell RCE
CVE-2021-31207MEDIUMbajo ataqueransomware06 abr 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyShell RCE
CVE-2021-34523CRITICALbajo ataqueransomware06 abr 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyShell RCE
CVE-2021-34473CRITICALbajo ataqueransomware06 abr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
VMware vRealize Operations (vROps) Manager SSRF RCE
CVE-2021-2198330 mar 2021
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authent
50RIESGO
abrir
Metasploit600
VMware vRealize Operations (vROps) Manager SSRF RCE
CVE-2021-21975HIGHbajo ataqueransomware30 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
Metasploit300
GravCMS Remote Command Execution
CVE-2021-21425CRITICAL29 mar 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
Metasploit0
macOS Gatekeeper check bypass
CVE-2021-30657MEDIUMbajo ataque25 mar 2021
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2
90RIESGO
abrir
Metasploit0
macOS Gatekeeper check bypass
CVE-2022-2261625 mar 2021
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey
18RIESGO
abrir
Metasploit600
Apache OFBiz SOAP Java Deserialization
CVE-2021-2629522 mar 2021
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RIESGO
abrir
Metasploit600
rConfig Vendors Auth File Upload RCE
CVE-2022-44384HIGH17 mar 2021
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP fi
36RIESGO
abrir
Metasploit600
F5 iControl REST Unauthenticated SSRF Token Generation RCE
CVE-2021-22986CRITICALbajo ataqueransomware10 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyLogon RCE
CVE-2021-27065HIGHbajo ataqueransomware02 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
VMware View Planner Unauthenticated Log File Upload RCE
CVE-2021-2197802 mar 2021
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val
60RIESGO
abrir
Metasploit300
Microsoft Exchange ProxyLogon Collector
CVE-2021-26855CRITICALbajo ataqueransomware02 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyLogon RCE
CVE-2021-26855CRITICALbajo ataqueransomware02 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit300
Microsoft Exchange ProxyLogon Scanner
CVE-2021-26855CRITICALbajo ataqueransomware02 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Veritas Backup Exec Agent Remote Code Execution
CVE-2021-27876HIGHbajo ataqueransomware01 mar 2021
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RIESGO
abrir
Metasploit600
Veritas Backup Exec Agent Remote Code Execution
CVE-2021-27878HIGHbajo ataqueransomware01 mar 2021
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RIESGO
abrir
Metasploit600
Veritas Backup Exec Agent Remote Code Execution
CVE-2021-27877HIGHbajo ataqueransomware01 mar 2021
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RIESGO
abrir
Metasploit300
FortiLogger Arbitrary File Upload Exploit
CVE-2021-337826 feb 2021
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RIESGO
abrir
Metasploit300
Wifi Mouse RCE
CVE-2022-321825 feb 2021
Necta WiFi Mouse (Mouse Server) client-side authentication bypass
40RIESGO
abrir
Metasploit600
SaltStack Salt API Unauthenticated RCE through wheel_async client
CVE-2021-2528125 feb 2021
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel
40RIESGO
abrir
Metasploit600
SaltStack Salt API Unauthenticated RCE through wheel_async client
CVE-2021-2528225 feb 2021
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable
40RIESGO
abrir
Metasploit300
Unified Remote Auth Bypass to RCE
CVE-2022-3229CRITICAL25 feb 2021
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication
55RIESGO
abrir
Metasploit600
IGEL OS Secure VNC/Terminal Command Injection RCE
CVE-2025-34082CRITICAL25 feb 2021
IGEL OS Secure Terminal and Secure Shadow Remote Code Execution
63RIESGO
abrir
Metasploit0
VMware vCenter Server Unauthenticated OVA File Upload RCE
CVE-2021-21972CRITICALbajo ataqueransomware23 feb 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
CVE-2021-25296HIGHbajo ataque13 feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.