Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.953exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.986VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RIESGO
abrir ↗Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
98RIESGO
abrir ↗Metasploit200
Win32k ConsoleControl Offset Confusion
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Metasploit600
Advantech iView Unauthenticated Remote Code Execution
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow a
30RIESGO
abrir ↗Metasploit200
Win32k ConsoleControl Offset Confusion
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir ↗Metasploit600
Micro Focus Operations Bridge Reporter Unauthenticated Command Injection
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The
100RIESGO
abrir ↗Metasploit600
NetMotion Mobility Server MvcUtil Java Deserialization
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code
40RIESGO
abrir ↗Metasploit300
NCR Command Center Agent Remote Code Execution
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (wit
40RIESGO
abrir ↗Metasploit600
Wordpress Plugin Modern Events Calendar - Authenticated Remote Code Execution
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RIESGO
abrir ↗Metasploit600
Sudo Heap-Based Buffer Overflow
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗Metasploit600
Apache Druid 0.20.0 Remote Command Execution
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir ↗Metasploit600
Lucee Administrator imgProcess.cfm Arbitrary File Write
Remote Code Exploit in Lucee Admin
78RIESGO
abrir ↗Metasploit600
Unauthenticated remote code execution in Ignition
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
48RIESGO
abrir ↗Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
Microsoft Exchange Remote Code Execution Vulnerability
65RIESGO
abrir ↗Metasploit300
Apache Flink JobManager Traversal
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗Metasploit600
Klog Server authenticate.php user Unauthenticated Command Injection
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RIESGO
abrir ↗Metasploit600
Nagios XI Prior to 5.8.0 - Plugins Filename Authenticated Remote Code Exection
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir ↗Metasploit600
HPE Systems Insight Manager AMF Deserialization RCE
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerabili
40RIESGO
abrir ↗Metasploit300
WordPress Total Upkeep Unauthenticated Backup Downloader
Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
36RIESGO
abrir ↗Metasploit600
TerraMaster TOS 4.2.06 or lower - Unauthenticated Remote Code Execution
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inje
40RIESGO
abrir ↗Metasploit600
TerraMaster TOS 4.2.06 or lower - Unauthenticated Remote Code Execution
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in
60RIESGO
abrir ↗Metasploit600
APISIX Admin API default access token RCE
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the
40RIESGO
abrir ↗Metasploit600
APISIX Admin API default access token RCE
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir ↗Metasploit300
WordPress Easy WP SMTP Password Reset
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in De
30RIESGO
abrir ↗Metasploit300
KOFFEE - Kia OFFensivE Exploit
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an atta
18RIESGO
abrir ↗Metasploit600
qdPM 9.1 Authenticated Arbitrary PHP File Upload (RCE)
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir ↗Metasploit0
Google Chrome versions before 87.0.4280.88 integer overflow during SimplfiedLowering phase
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir ↗Metasploit0
Firefox MCallGetProperty Write Side Effects Use After Free Exploit
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable
30RIESGO
abrir ↗Metasploit600
OpenTSDB 2.4.0 unauthenticated command injection
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. Th
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.