Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
IBM TM1 / Planning Analytics Unauthenticated Remote Code Execution
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated use
100RIESGO
abrir ↗Metasploit600
Citrix ADC (NetScaler) Directory Traversal RCE
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗Metasploit300
Citrix ADC (NetScaler) Directory Traversal Scanner
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗Metasploit300
TVT NVMS-1000 Directory Traversal
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir ↗Metasploit600
OpenBSD Dynamic Loader chpass Privilege Escalation
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir ↗Metasploit300
Microsoft Windows Uninitialized Variable Local Privilege Elevation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗Metasploit600
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir ↗Metasploit600
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir ↗Metasploit300
Anviz CrossChex Buffer Overflow
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
50RIESGO
abrir ↗Metasploit300
QNAP QTS and Photo Station Local File Inclusion
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RIESGO
abrir ↗Metasploit300
QNAP QTS and Photo Station Local File Inclusion
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RIESGO
abrir ↗Metasploit300
QNAP QTS and Photo Station Local File Inclusion
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RIESGO
abrir ↗Metasploit600
Liferay Portal Java Unmarshalling via JSONWS RCE
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir ↗Metasploit300
WordPress Email Subscribers and Newsletter Hash SQLi Scanner
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RIESGO
abrir ↗Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RIESGO
abrir ↗Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RIESGO
abrir ↗Metasploit600
Optergy Proton and Enterprise BMS Command Injection using a backdoor
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RIESGO
abrir ↗Metasploit600
Microsoft Spooler Local Privilege Elevation Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
41RIESGO
abrir ↗Metasploit600
Windows Update Orchestrator unchecked ScheduleWork call
An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file oper
30RIESGO
abrir ↗Metasploit300
Microsoft Spooler Local Privilege Elevation Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
61RIESGO
abrir ↗Metasploit600
FreeSWITCH Event Socket Command Execution
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RIESGO
abrir ↗Metasploit0
Kibana Timelion Prototype Pollution RCE
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗Metasploit600
Apache Solr Remote Code Execution via Velocity Template
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir ↗Metasploit600
Linear eMerge E3-Series Access Controller Command Injection
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir ↗Metasploit600
rConfig install Command Execution
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir ↗Metasploit400
Nostromo Directory Traversal Remote Command Execution
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir ↗Metasploit600
Solaris xscreensaver log Privilege Escalation
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir ↗Metasploit300
ThinVNC Directory Traversal
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.