Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
WordPress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir ↗Exploit-DB
OpenEDX platform Ironwood 2.5 - Remote Code Execution
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>Ne
28RIESGO
abrir ↗Exploit-DB
BIND - 'TSIG' Denial of Service
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RIESGO
abrir ↗Exploit-DB
Submitty 20.04.01 - Persistent Cross-Site Scripting
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir ↗Exploit-DB
Mikrotik Router Monitoring System 1.2.3 - 'community' SQL Injection
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community
23RIESGO
abrir ↗Exploit-DB
Oracle Hospitality RES 3700 5.7 - Remote Code Execution
Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported versi
28RIESGO
abrir ↗Exploit-DB
HP LinuxKI 6.01 - Remote Command Injection
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RIESGO
abrir ↗Exploit-DB
WordPress Plugin ChopSlider 3.4 - 'id' SQL Injection
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RIESGO
abrir ↗Exploit-DB
Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
Cisco Digital Network Architecture Center Stored Cross-Site Scripting Vulnerability
33RIESGO
abrir ↗Exploit-DB
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Moni
28RIESGO
abrir ↗Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution / Privileges Escalation
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir ↗Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir ↗Exploit-DB
Saltstack 3000.1 - Remote Code Execution
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir ↗Exploit-DB
Saltstack 3000.1 - Remote Code Execution
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir ↗Exploit-DB
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RIESGO
abrir ↗Exploit-DB
Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in
23RIESGO
abrir ↗Exploit-DB
Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported version
41RIESGO
abrir ↗Exploit-DB
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
Unraid through 6.8.0 allows Remote Code Execution.
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
Unraid 6.8.0 allows authentication bypass.
100RIESGO
abrir ↗Exploit-DB
Cisco IP Phone 11.7 - Denial of service (PoC)
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.