Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.329exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.482VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Control Web Panel /admin/index.php Unauthenticated RCE
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /
56RIESGO
abrir ↗Metasploit600
HPE OneView unauthenticated RCE
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir ↗Metasploit600
FreeBSD rtsold/rtsol DNSSL Command Injection
Remote code execution via ND6 Router Advertisements
56RIESGO
abrir ↗Metasploit600
FreePBX endpoint SQLi to RCE
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir ↗Metasploit300
FreePBX Custom Extension SQL Injection
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RIESGO
abrir ↗Metasploit600
FreePBX endpoint SQLi to RCE
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RIESGO
abrir ↗Metasploit600
FreePBX firmware file upload
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir ↗Metasploit300
FreePBX Custom Extension SQL Injection
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir ↗Metasploit600
FreePBX firmware file upload
FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter
48RIESGO
abrir ↗Metasploit300
Gladinet CentreStack/Triofox Access Ticket Forge
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RIESGO
abrir ↗Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗Metasploit600
WordPress ACF Extended Unauthenticated RCE via prepare_form()
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RIESGO
abrir ↗Metasploit600
Eclipse Che machine-exec Unauthenticated RCE
Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333
43RIESGO
abrir ↗Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
36RIESGO
abrir ↗Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
36RIESGO
abrir ↗Metasploit300
GeoServer WMS GetMap XXE Arbitrary File Read
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir ↗Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
N-central unauthenticated sessionID generation
60RIESGO
abrir ↗Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
N-central Multiple XXE Injection Vulnerabilities
68RIESGO
abrir ↗Metasploit300
Fortinet FortiWeb create new local admin
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗Metasploit600
Fortinet FortiWeb unauthenticated RCE
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RIESGO
abrir ↗Metasploit600
Fortinet FortiWeb unauthenticated RCE
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗Metasploit600
FreePBX filestore authenticated command injection
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RIESGO
abrir ↗Metasploit600
Monsta FTP downloadFile Remote Code Execution
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗Metasploit600
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RIESGO
abrir ↗Metasploit600
WordPress King Addons for Elementor Unauthenticated Privilege Escalation to RCE
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
43RIESGO
abrir ↗Metasploit600
Taiga tribe_gig authenticated unserialize remote code execution
Taiga Authenticated Remote Code Execution
43RIESGO
abrir ↗Metasploit600
Magento SessionReaper
Adobe Commerce | Improper Input Validation (CWE-20)
100RIESGO
abrir ↗Metasploit500
Windows Server Update Service Deserialization Remote Code Execution
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit600
SmarterTools SmarterMail GUID File Upload Vulnerability
Upload Arbitrary Files
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.