Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RIESGO
abrir ↗Metasploit600
VICIdial Authenticated Remote Code Execution
VICIdial Authenticated Remote Code Execution
58RIESGO
abrir ↗Metasploit300
Vicidial SQL Injection Time-based Admin Credentials Enumeration
VICIdial Unauthenticated SQL Injection
85RIESGO
abrir ↗Metasploit600
SPIP BigUp Plugin Unauthenticated RCE
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir ↗Metasploit600
Wordpress LiteSpeed Cache plugin cookie theft
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗Metasploit300
WhatsUp Gold SQL Injection (CVE-2024-6670)
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RIESGO
abrir ↗Metasploit600
Moodle Remote Code Execution (CVE-2024-43425)
Moodle: remote code execution via calculated question types
78RIESGO
abrir ↗Metasploit600
GiveWP Unauthenticated Donation Process Exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RIESGO
abrir ↗Metasploit600
GiveWP Unauthenticated Donation Process Exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir ↗Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RIESGO
abrir ↗Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
Traccar's unrestricted file upload vulnerability in device image upload could lead to remote code execution
48RIESGO
abrir ↗Metasploit300
SolarWinds Web Help Desk Backdoor (CVE-2024-28987)
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir ↗Metasploit600
SPIP Unauthenticated RCE via porte_plume Plugin
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir ↗Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi
36RIESGO
abrir ↗Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overw
43RIESGO
abrir ↗Metasploit300
Camaleon CMS Directory Traversal CVE-2024-46987
Arbitrary path traversal in Camaleon CMS
61RIESGO
abrir ↗Metasploit500
Asterisk AMI Originate Authenticated RCE
Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
36RIESGO
abrir ↗Metasploit300
Ivanti Virtual Traffic Manager Authentication Bypass (CVE-2024-7593)
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RIESGO
abrir ↗Metasploit600
Calibre Python Code Injection (CVE-2024-6782)
Calibre Remote Code Execution
85RIESGO
abrir ↗Metasploit600
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗Metasploit600
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir ↗Metasploit600
Acronis Cyber Infrastructure default password remote code execution
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
85RIESGO
abrir ↗Metasploit300
Cisco Smart Software Manager (SSM) On-Prem Account Takeover (CVE-2024-20419)
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
85RIESGO
abrir ↗Metasploit600
ProjectSend r1295 - r1605 Unauthenticated Remote Code Execution
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir ↗Metasploit600
Geoserver unauthenticated Remote Code Execution
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗Metasploit600
Authenticated RCE in Splunk (splunk_archiver app)
Remote Code Execution (RCE) through an external lookup due to “copybuckets.py“ script in the “splunk_archiver“ application in Splunk Enterprise
36RIESGO
abrir ↗Metasploit300
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
MOVEit Transfer Authentication Bypass Vulnerability
85RIESGO
abrir ↗Metasploit300
Fortra FileCatalyst Workflow SQL Injection (CVE-2024-5276)
SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
65RIESGO
abrir ↗Metasploit500
vCenter Sudo Privilege Escalation
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An auth
36RIESGO
abrir ↗Metasploit600
Windows Access Mode Mismatch LPE in ks.sys
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.