Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Serv-U FTP Server prepareinstallation Privilege Escalation
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir ↗Metasploit300
Supra Smart Cloud TV Remote File Inclusion
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcas
43RIESGO
abrir ↗Metasploit600
Ahsay Backup v7.x-v8.1.1.50 (authenticated) file upload
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RIESGO
abrir ↗Metasploit600
Atlassian Crowd pdkinstall Unauthenticated Plugin Upload RCE
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RIESGO
abrir ↗Metasploit300
OpenEMR 5.0.1 Patch 6 SQLi Dump
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/
23RIESGO
abrir ↗Metasploit600
ATutor 2.2.4 - Directory Traversal / Remote Code Execution,
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathnam
40RIESGO
abrir ↗Metasploit600
Webmin Package Updates Remote Command Execution
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir ↗Metasploit600
Cisco Prime Infrastructure Health Monitor TarArchive Directory Traversal Vulnerability
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RIESGO
abrir ↗Metasploit600
DLINK DWL-2600 Authenticated Remote Command Injection
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Config
60RIESGO
abrir ↗Metasploit600
IBM Websphere Application Server Network Deployment Untrusted Data Deserialization Remote Code Execution
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with
85RIESGO
abrir ↗Metasploit300
CVE-2019-0708 BlueKeep Microsoft Remote Desktop RCE Check
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir ↗Metasploit0
CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir ↗Metasploit600
Shopware createInstanceFromNamedArguments PHP Object Instantiation RCE
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiat
40RIESGO
abrir ↗Metasploit600
Shopware createInstanceFromNamedArguments PHP Object Instantiation RCE
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t
43RIESGO
abrir ↗Metasploit600
Barco WePresent file_transfer.cgi Command Injection
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir ↗Metasploit600
GetSimpleCMS Unauthenticated RCE
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
60RIESGO
abrir ↗Metasploit600
WP Database Backup RCE
WP Database Backup < 5.2 - Unauthenticated OS Command Injection
68RIESGO
abrir ↗Metasploit300
Pulse Secure VPN Arbitrary File Disclosure
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir ↗Metasploit600
Pulse Secure VPN Arbitrary Command Execution
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir ↗Metasploit600
Oracle Weblogic Server Deserialization RCE - AsyncResponseService
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir ↗Metasploit300
Spring Cloud Config Server Directory Traversal
Directory Traversal with spring-cloud-config-server
60RIESGO
abrir ↗Metasploit600
SmarterTools SmarterMail less than build 6985 - .NET Deserialization Remote Code Execution
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RIESGO
abrir ↗Metasploit300
Oracle Application Testing Suite Post-Auth DownloadServlet Directory Traversal
Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen
18RIESGO
abrir ↗Metasploit300
Remote Mouse RCE
Emote Interactive Remote Mouse Server command injection due to weak encoding
63RIESGO
abrir ↗Metasploit600
Kentico CMS Staging SyncServer Unserialize Remote Command Execution
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RIESGO
abrir ↗Metasploit600
Mac OS X Feedback Assistant Race Condition
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A mali
43RIESGO
abrir ↗Metasploit600
Mac OS X TimeMachine (tmdiagnose) Command Injection Privilege Escalation
This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to
38RIESGO
abrir ↗Metasploit600
Apache Tomcat CGIServlet enableCmdLineArguments Vulnerability
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir ↗Metasploit300
AppXSvc Hard Link Privilege Escalation
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.