Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.955exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.988VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
PEAR Archive_Tar 1.4.10 Arbitrary File Write
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper
100RIESGO
abrir ↗Metasploit600
Monitorr unauthenticated Remote Code Execution (RCE)
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the s
40RIESGO
abrir ↗Metasploit600
WordPress AIT CSV Import Export Unauthenticated Remote Code Execution
AIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File Upload
43RIESGO
abrir ↗Metasploit600
Acronis TrueImage XPC Privilege Escalation
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC
18RIESGO
abrir ↗Metasploit300
Abandoned Cart for WooCommerce SQLi Scanner
WordPress Recover abandoned cart for WooCommerce plugin <= 2.5 - SQL Injection Vulnerability
43RIESGO
abrir ↗Metasploit600
Git Remote Code Execution via git-lfs (CVE-2020-27955)
Git LFS 2.12.0 allows Remote Code Execution.
40RIESGO
abrir ↗Metasploit600
SaltStack Salt REST API Arbitrary Command Execution
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authent
30RIESGO
abrir ↗Metasploit600
SaltStack Salt REST API Arbitrary Command Execution
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RIESGO
abrir ↗Metasploit600
Rapid7 Metasploit Framework msfvenom APK Template Command Injection
Client-Side Command Injection in Rapid7 Metasploit
68RIESGO
abrir ↗Metasploit600
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.
85RIESGO
abrir ↗Metasploit600
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
Arbitrary code execution vulnerability on multiple Micro Focus products
58RIESGO
abrir ↗Metasploit600
Micro Focus Operations Bridge Manager Authenticated Remote Code Execution
Arbitrary code execution vulnerability on multiple Micro Focus products
58RIESGO
abrir ↗Metasploit600
Micro Focus Operations Bridge Manager / Reporter Local Privilege Escalation
Code execution with escalated privilegesn vlnerability in Operation bridge Manager and Operations Bridge (containerized) products.
36RIESGO
abrir ↗Metasploit600
Micro Focus Operations Bridge Manager / Reporter Local Privilege Escalation
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
18RIESGO
abrir ↗Metasploit600
Pulse Secure VPN gzip RCE
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform
100RIESGO
abrir ↗Metasploit300
WordPress Loginizer log SQLi Scanner
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa
30RIESGO
abrir ↗Metasploit300
Oracle Solaris SunSSH PAM parse_user_name() Buffer Overflow
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir ↗Metasploit600
NSClient++ 0.5.2.35 - ExternalScripts Authenticated Remote Code Execution
NSClient++ Authenticated Remote Code Execution via ExternalScripts API
36RIESGO
abrir ↗Metasploit600
NSClient++ 0.5.2.35 - Privilege escalation
NSClient++ 0.5.2.35 Local Privilege Escalation via ExternalScripts and Web Interface
36RIESGO
abrir ↗Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗Metasploit600
Nagios XI 5.5.0-5.7.3 - Snmptrap Authenticated Remote Code Exection
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user
30RIESGO
abrir ↗Metasploit600
Nagios XI 5.6.0-5.7.3 - Mibs.php Authenticated Remote Code Exection
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RIESGO
abrir ↗Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗Metasploit600
Microsoft SharePoint Server-Side Include and ViewState RCE
Microsoft SharePoint Remote Code Execution Vulnerability
58RIESGO
abrir ↗Metasploit600
Gogs Git Hooks Remote Code Execution
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privile
40RIESGO
abrir ↗Metasploit600
Gitea Git Hooks Remote Code Execution
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer envir
40RIESGO
abrir ↗Metasploit300
SAP Solution Manager remote unauthorized OS commands execution
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir ↗Metasploit300
SAP Solution Manager remote unauthorized OS commands execution
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir ↗Metasploit600
FlexDotnetCMS Arbitrary ASP File Upload
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and e
40RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.