Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Nexus Repository Manager Java EL Injection RCE
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir ↗Metasploit300
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo
23RIESGO
abrir ↗Metasploit300
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an atta
18RIESGO
abrir ↗Metasploit400
Pi-Hole DHCP MAC OS Command Execution
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir ↗Metasploit600
GitLab File Read Remote Code Execution
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
30RIESGO
abrir ↗Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
68RIESGO
abrir ↗Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer
61RIESGO
abrir ↗Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the sl
40RIESGO
abrir ↗Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware
48RIESGO
abrir ↗Metasploit600
Grandstream UCM62xx IP PBX sendPasswordEmail RCE
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte
100RIESGO
abrir ↗Metasploit600
macOS cfprefsd Arbitrary File Write Local Privilege Escalation
A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Cata
18RIESGO
abrir ↗Metasploit0
Safari in Operator Side Effect Exploit
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa
40RIESGO
abrir ↗Metasploit0
Safari in Operator Side Effect Exploit
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able
18RIESGO
abrir ↗Metasploit0
Safari in Operator Side Effect Exploit
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A malicious process may ca
18RIESGO
abrir ↗Metasploit600
VMware Fusion USB Arbitrator Setuid Privilege Escalation
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RIESGO
abrir ↗Metasploit600
Vesta Control Panel Authenticated Remote Code Execution
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint.
40RIESGO
abrir ↗Metasploit400
SMBv3 Compression Buffer Overflow
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Metasploit200
SMBv3 Compression Buffer Overflow
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Metasploit300
vBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
40RIESGO
abrir ↗Metasploit0
vBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
40RIESGO
abrir ↗Metasploit400
Rconfig 3.x Chained Remote Code Execution
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RIESGO
abrir ↗Metasploit400
Rconfig 3.x Chained Remote Code Execution
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RIESGO
abrir ↗Metasploit300
CVE-2020-1170 Cloud Filter Arbitrary File Creation EOP
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RIESGO
abrir ↗Metasploit600
Background Intelligent Transfer Service Arbitrary File Move Privilege Elevation Vulnerability
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir ↗Metasploit600
Pandora FMS Ping Authenticated Remote Code Execution
Pandora FMS Authenticated Remote Code Execution via Ping Module
36RIESGO
abrir ↗Metasploit500
ManageEngine Desktop Central Java Deserialization
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RIESGO
abrir ↗Metasploit600
Metasploit Libnotify Plugin Arbitrary Command Execution
Metasploit Framework Plugin Libnotify Command Injection
28RIESGO
abrir ↗Metasploit600
SharePoint Workflows XOML Injection
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RIESGO
abrir ↗Metasploit600
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RIESGO
abrir ↗Metasploit600
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.