Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir ↗Exploit-DB
CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF)
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute
23RIESGO
abrir ↗Exploit-DB
Elasticsearch ECE 7.13.3 - Anonymous Database Dump
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
28RIESGO
abrir ↗Exploit-DB
ElasticSearch 7.13.3 - Memory disclosure
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
60RIESGO
abrir ↗Exploit-DB
Microsoft SharePoint Server 2019 - Remote Code Execution (2)
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RIESGO
abrir ↗Exploit-DB
Webmin 1.973 - 'run.cgi' Cross-Site Request Forgery (CSRF)
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's ru
35RIESGO
abrir ↗Exploit-DB
WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated)
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
50RIESGO
abrir ↗Exploit-DB
PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQ
23RIESGO
abrir ↗Exploit-DB
Aruba Instant 8.7.1.0 - Arbitrary File Modification
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RIESGO
abrir ↗Exploit-DB
ForgeRock Access Manager 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.19 < 5.9 - 'Netfilter Local Privilege Escalation
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir ↗Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RIESGO
abrir ↗Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve
35RIESGO
abrir ↗Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
23RIESGO
abrir ↗Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s
35RIESGO
abrir ↗Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RIESGO
abrir ↗Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
28RIESGO
abrir ↗Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s
28RIESGO
abrir ↗Exploit-DB
Aruba Instant (IAP) - Remote Code Execution
A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve
43RIESGO
abrir ↗Exploit-DB
WordPress Plugin Popular Posts 5.3.2 - Remote Code Execution (RCE) (Authenticated)
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RIESGO
abrir ↗Exploit-DB
Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RIESGO
abrir ↗Exploit-DB
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2)
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote
28RIESGO
abrir ↗Exploit-DB
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided
50RIESGO
abrir ↗Exploit-DB
Apache Tomcat 9.0.0.M1 - Open Redirect
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a r
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir ↗Exploit-DB
WordPress Plugin Plainview Activity Monitor 20161228 - Remote Code Execution (RCE) (Authenticated) (2)
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir ↗Exploit-DB
Pallets Werkzeug 0.15.4 - Path Traversal
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated)
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated)
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated)
Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.