Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
78.324 exploits
VulnCheck XDB
initial-access
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir ↗VulnCheck XDB
initial-access
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
WildfootW/CVE-2018-15473_OpenSSH_7.7
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB
SmarterMail Build 6985 - Remote Code Execution
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RIESGO
abrir ↗GitHub PoC
WildfootW/CVE-2007-2447_Samba_3.0.25rc3
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗GitHub PoC★ 157
Exchange2010 authorized RCE
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir ↗GitHub PoC★ 64
ka1n4t/CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir ↗GitHub PoC★ 1
Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风险极大。提醒我校Apache Struts用户尽快采取安全措施阻止漏洞攻击。
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir ↗GitHub PoC★ 157
weaponized tool for CVE-2020-17144
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir ↗GitHub PoC
Remote code execution in Mediawiki Score
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of
48RIESGO
abrir ↗VulnCheck XDB
initial-access
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
28RIESGO
abrir ↗VulnCheck XDB
local
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗VulnCheck XDB
infoleak
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Metasploit600
APISIX Admin API default access token RCE
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir ↗Exploit-DB
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell)
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir ↗Metasploit600
APISIX Admin API default access token RCE
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the
40RIESGO
abrir ↗Metasploit300
WordPress Easy WP SMTP Password Reset
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in De
30RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE: 2017-5638 - Apache Struts2 S2-045
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC
Exploit for the vulnerability CVE-2007-2447
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗GitHub PoC
[qdPM < 9.1 - Remote Code Execution](https://www.exploit-db.com/exploits/48146)
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a
28RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.