Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
Magento XXE Unserialize Arbitrary File Read
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗Metasploit600
Windows Kernel Time of Check Time of Use LPE in AuthzBasepCopyoutInternalSecurityAttributes
Win32k Elevation of Privilege Vulnerability
36RIESGO
abrir ↗Metasploit600
PHP CGI Argument Injection Remote Code Execution
Argument Injection in PHP-CGI
100RIESGO
abrir ↗Metasploit600
Telerik Report Server Auth Bypass and Deserialization RCE
Progress Telerik Report Server Deserialization
55RIESGO
abrir ↗Metasploit300
Telerik Report Server Auth Bypass
Registration Authentication Bypass Vulnerability
100RIESGO
abrir ↗Metasploit600
Telerik Report Server Auth Bypass and Deserialization RCE
Registration Authentication Bypass Vulnerability
100RIESGO
abrir ↗Metasploit0
macOS PackageKit ZSH Environment Privilege Escalation
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to
36RIESGO
abrir ↗Metasploit600
Apache OFBiz forgotPassword/ProgramExport RCE
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir ↗Metasploit600
Apache OFBiz forgotPassword/ProgramExport RCE
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir ↗Metasploit600
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir ↗Metasploit300
Ivanti EPM RecordGoodApp SQLi RCE
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RIESGO
abrir ↗Metasploit600
WordPress Hash Form Plugin RCE
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RIESGO
abrir ↗Metasploit600
Atlassian Confluence Administrator Code Macro Remote Code Execution
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RIESGO
abrir ↗Metasploit600
Cacti Import Packages RCE
Cacti RCE vulnerability when importing packages
85RIESGO
abrir ↗Metasploit600
DIAEnergie SQL Injection (CVE-2024-4548)
Delta Electronics DIAEnergie SQL Injection
48RIESGO
abrir ↗Metasploit600
Ollama Model Registry Path Traversal RCE
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,
78RIESGO
abrir ↗Metasploit600
Flowmon Unauthenticated Command Injection
Flowmon Unauthenticated Command Injection Vulnerability
85RIESGO
abrir ↗Metasploit600
Apache HugeGraph Gremlin RCE
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir ↗Metasploit600
FortiNet FortiClient Endpoint Management Server FCTID SQLi to RCE
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio
100RIESGO
abrir ↗Metasploit600
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir ↗Metasploit300
Netdata ndsudo privilege escalation
ndsudo: local privilege escalation via untrusted search path
36RIESGO
abrir ↗Metasploit600
Chaos RAT XSS to RCE
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via th
28RIESGO
abrir ↗Metasploit600
AVideo WWBNIndex Plugin Unauthenticated RCE
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath
68RIESGO
abrir ↗Metasploit600
pgAdmin Binary Path API RCE
Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4
48RIESGO
abrir ↗Metasploit600
Kemp LoadMaster Unauthenticated Command Injection
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir ↗Metasploit600
Progress Flowmon Local sudo privilege escalation
Flowmon Unauthenticated Command Injection Vulnerability
85RIESGO
abrir ↗Metasploit600
Kemp LoadMaster Local sudo privilege escalation
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir ↗Metasploit600
Gibbon School Platform Authenticated PHP Deserialization Vulnerability
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POS
48RIESGO
abrir ↗Metasploit600
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.