Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
79.107 exploits
VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC
CVE-2018-7600 0-Day Exploit (cyber-warrior.org)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Metasploit600
Cacti color filter authenticated SQLi to RCE
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir ↗GitHub PoC★ 86
LPE for CVE-2020-1054 targeting Windows 7 x64
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir ↗Metasploit300
AnyDesk GUI Format String Write
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RIESGO
abrir ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗Exploit-DB
Gila CMS 1.11.8 - 'query' SQL Injection
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
28RIESGO
abrir ↗GitHub PoC★ 721
Support ALL Windows Version
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir ↗GitHub PoC★ 30
CVE-2020-5410 Spring Cloud Config directory traversal vulnerability
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir ↗GitHub PoC
Description and public exploit for CVE-2020-12712
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RIESGO
abrir ↗Metasploit300
Netgear R6700v3 Unauthenticated LAN Admin Password Reset
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700
50RIESGO
abrir ↗GitHub PoC★ 1
A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir ↗Metasploit300
Netgear R6700v3 Unauthenticated LAN Admin Password Reset
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700
58RIESGO
abrir ↗GitHub PoC
Description and public exploit for CVE-2020-12712
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RIESGO
abrir ↗Exploit-DB
SOS JobScheduler 1.13.3 - Stored Password Decryption
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RIESGO
abrir ↗GitHub PoC
sionnx/cve-2003-0282
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters bet
28RIESGO
abrir ↗VulnCheck XDB
client-side
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir ↗GitHub PoC★ 3
for 供養
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir ↗GitHub PoC★ 23
cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗Exploit-DB
Sysax MultiServer 6.90 - Reflected Cross Site Scripting
An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
23RIESGO
abrir ↗GitHub PoC
freshdemo/ApacheStruts-CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗VulnCheck XDB
local
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir ↗GitHub PoC
Struts 2.5 - 2.5.12 REST Plugin XStream RCE
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir ↗Metasploit600
Inductive Automation Ignition Remote Code Execution
The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.