Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8811Nuclei 4349Metasploit 3488✓ solo verificadosrecientespopularesriesgo
78.258 exploits
Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RIESGO
abrir ↗GitHub PoC
Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RIESGO
abrir ↗Exploit-DB
Composr 10.0.36 - Remote Code Execution
Composr 10.0.36 allows upload and execution of PHP files.
28RIESGO
abrir ↗Exploit-DB
Composr CMS 10.0.36 - Cross Site Scripting
Composr 10.0.36 allows XSS in an XML script.
23RIESGO
abrir ↗GitHub PoC
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir ↗Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
Cisco Small Business RV Series Routers Vulnerabilities
40RIESGO
abrir ↗Exploit-DB
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RIESGO
abrir ↗Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
Cisco Small Business RV Series Routers Vulnerabilities
50RIESGO
abrir ↗Exploit-DB
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RIESGO
abrir ↗Metasploit600
Microsoft Exchange ProxyShell RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
infoleak
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir ↗Metasploit600
Microsoft Exchange ProxyShell RCE
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC
Exploit for CVE-2012-2982
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir ↗Metasploit600
Microsoft Exchange ProxyShell RCE
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 6
[CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE)
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir ↗Exploit-DB
Google Chrome 81.0.4044 V8 - Remote Code Execution
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
28RIESGO
abrir ↗GitHub PoC
pwn3z/CVE-2019-19781-Citrix
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir ↗GitHub PoC★ 37
vRealize RCE + Privesc (CVE-2021-21975, CVE-2021-21983, CVE-0DAY-?????)
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir ↗Exploit-DB
Google Chrome 86.0.4240 V8 - Remote Code Execution
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir ↗GitHub PoC★ 1
Exploit Code for CVE-2020-1472 aka Zerologon
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC
capturingcats/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC★ 3
Exploiting CVE-2014-7205 by injecting arbitrary JavaScript resulting in Remote Code Execution.
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RIESGO
abrir ↗GitHub PoC
delina1/CVE-2018-8174
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗GitHub PoC
delina1/CVE-2018-8174_EXP
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗GitHub PoC★ 1
CVE-2017-9805-Exploit
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2017-9805-Exploit
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.