Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.401 exploits
GitHub PoC★ 3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RIESGO
abrir ↗GitHub PoC★ 34
Perform With Mass Exploiter In Joomla 4.2.8.
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗GitHub PoC
Ge-Per/Scanner-CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗Exploit-DB
Suprema BioStar 2 v2.8.16 - SQL Injection
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs
33RIESGO
abrir ↗Exploit-DB
Microsoft Excel 365 MSO (Version 2302 Build 16.0.16130.20186) 64-bit - Remote Code Execution (RCE)
Microsoft Excel Remote Code Execution Vulnerability
41RIESGO
abrir ↗Metasploit300
Jasmin Ransomware Web Server Unauthenticated Directory Traversal
Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive infor
28RIESGO
abrir ↗Metasploit300
Jasmin Ransomware Web Server Unauthenticated SQL Injection
codesiddhant Jasmin Ransomware checklogin.php sql injection
28RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! v4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗Exploit-DB
FortiRecorder 6.4.3 - Denial of Service
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RIESGO
abrir ↗Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RIESGO
abrir ↗Exploit-DB
Goanywhere Encryption helper 7.1.1 - Remote Code Execution (RCE)
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RIESGO
abrir ↗Exploit-DB
Altenergy Power Control Software C1.2.5 - OS command injection
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RIESGO
abrir ↗Exploit-DB
ZCBS/ZBBS/ZPBS v4.14k - Reflected Cross-Site Scripting (XSS)
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RIESGO
abrir ↗Exploit-DB
pfsenseCE v2.6.0 - Anti-brute force protection bypass
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RIESGO
abrir ↗Exploit-DB
Adobe Connect 11.4.5 - Local File Disclosure
Adobe Connect Improper Access Control Security feature bypass
70RIESGO
abrir ↗Exploit-DB
X2CRM v6.6/6.9 - Stored Cross-Site Scripting (XSS) (Authenticated)
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via
33RIESGO
abrir ↗Exploit-DB
Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)
Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface
33RIESGO
abrir ↗Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RIESGO
abrir ↗Exploit-DB
ENTAB ERP 1.0 - Username PII leak
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames
33RIESGO
abrir ↗Exploit-DB
RSA NetWitness Platform 12.2 - Incorrect Access Control / Code Execution
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RIESGO
abrir ↗Exploit-DB
Symantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)
An authenticated user can embed malicious content with XSS into the admin group policy page.
33RIESGO
abrir ↗Exploit-DB
X2CRM v6.6/6.9 - Reflected Cross-Site Scripting (XSS) (Authenticated)
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v
33RIESGO
abrir ↗GitHub PoC
ReachabilityOrg/cve-2022-42889-text4shell-docker
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗GitHub PoC
jedai47/cve-2018-17182
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir ↗Exploit-DB
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
IBM Aspera Faspex code execution
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.