Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RIESGO
abrir ↗Metasploit600
Invoice Ninja unauthenticated PHP Deserialization Vulnerability
Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_
36RIESGO
abrir ↗Metasploit600
InvoiceShelf unauthenticated PHP Deserialization Vulnerability
A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote com
55RIESGO
abrir ↗Metasploit600
Cleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can impo
95RIESGO
abrir ↗Metasploit300
LINQPad Deserialization
LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(
36RIESGO
abrir ↗Metasploit600
mySCADA myPRO Manager Unauthenticated Command Injection (CVE-2024-47407)
mySCADA myPRO OS Command Injection
55RIESGO
abrir ↗Metasploit600
Pandora FMS authenticated command injection leading to RCE via LDAP using default DB password
Command Injection leading to RCE via LDAP Misconfiguration
50RIESGO
abrir ↗Metasploit500
Ubuntu needrestart Privilege Escalation
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tric
41RIESGO
abrir ↗Metasploit600
Palo Alto Networks PAN-OS Management Interface Unauthenticated Remote Code Execution
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir ↗Metasploit600
Palo Alto Networks PAN-OS Management Interface Unauthenticated Remote Code Execution
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir ↗Metasploit600
LibreNMS Authenticated RCE (CVE-2024-51092)
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr
43RIESGO
abrir ↗Metasploit600
WordPress WP Time Capsule Arbitrary File Upload to RCE
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗Metasploit600
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗Metasploit600
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗Metasploit600
Prison Management System 1.0 Authenticated RCE via Unrestricted File Upload
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the f
36RIESGO
abrir ↗Metasploit600
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RIESGO
abrir ↗Metasploit600
CyberPanel Multi CVE Pre-auth RCE
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir ↗Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RIESGO
abrir ↗Metasploit600
CyberPanel Multi CVE Pre-auth RCE
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir ↗Metasploit600
Fortinet FortiManager Unauthenticated RCE
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir ↗Metasploit300
OneDev Unauthenticated Arbitrary File Read
OneDev vulnerable to arbitrary file reading for unauthenticated user
41RIESGO
abrir ↗Metasploit600
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
Expedition: Missing Authentication Leads to Admin Account Takeover
100RIESGO
abrir ↗Metasploit600
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RIESGO
abrir ↗Metasploit600
Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Se
55RIESGO
abrir ↗Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
libppd's ppdCreatePPDFromIPP2 function does not sanitize IPP attributes when creating the PPD buffer
48RIESGO
abrir ↗Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir ↗Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
libcupsfilters's cfGetPrinterAttributes5 does not validate IPP attributes returned from an IPP server
58RIESGO
abrir ↗Metasploit300
WordPress TI WooCommerce Wishlist SQL Injection (CVE-2024-43917)
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RIESGO
abrir ↗Metasploit300
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.