Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleicritical
Apache Airflow <=1.10.10 - Command Injection
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect t
30RIESGO
abrir ↗Nucleicritical
Ghostcat - Apache Tomcat - AJP File Read/Inclusion Vulnerability
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗Nucleihigh
Pure-FTPd 1.0.48 - Denial of Service
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the con
18RIESGO
abrir ↗Nucleihigh
Pure-FTPd ≤ 1.0.49 - DoS via Uninitialized Pointer
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases
18RIESGO
abrir ↗Nucleimedium
Pure-FTPd 1.0.24 - Security Vulnerability
An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function i
18RIESGO
abrir ↗Nucleihigh
Veritas Backup Exec - Broken Authentication
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RIESGO
abrir ↗Nucleihigh
vsftpd < 3.0.3 - DoS
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
18RIESGO
abrir ↗Nucleicritical
NCR Command Center Agent 16.3 - Remote Command Execution
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (wit
40RIESGO
abrir ↗Nucleihigh
Pure-FTPd 1.0.23 < 1.0.50 - Arbitrary File Upload
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of
18RIESGO
abrir ↗Nucleicritical
Redis Sandbox Escape - Remote Code Execution
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir ↗Nucleicritical
CouchDB Erlang Distribution - Remote Command Execution
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir ↗Nucleihigh
muhttpd <=1.1.5 - Local Inclusion
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL wi
23RIESGO
abrir ↗Nucleihigh
TitanFTP move-file Function ≤ 1.94.1205 - Path Traversal
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RIESGO
abrir ↗Nucleicritical
RocketMQ <= 5.1.0 - Remote Code Execution
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir ↗Nucleicritical
Apache RocketMQ - Remote Command Execution
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir ↗Nucleicritical
Fortinet Forticlient Endpoint Management Server - SQL Injection
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio
100RIESGO
abrir ↗Nucleihigh
ProFTPD < 1.3.8a - DoS via Out-of-Bounds Read
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandl
18RIESGO
abrir ↗Nucleicritical
Fortinet FortiSIEM - OS Command Injection
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RIESGO
abrir ↗Nucleihigh
Pure-FTPd < 1.0.52 - Buffer Overflow
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the
36RIESGO
abrir ↗Nucleihigh
ProFTPD ≤ 1.3.8b - Privilege Escalation via mod_sql
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th
36RIESGO
abrir ↗Nucleicritical
Fortinet FortiSIEM - OS Command Injection
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
75RIESGO
abrir ↗Nucleicritical
Güralp Systems FMUS Series - Unauthenticated Access
Güralp Systems FMUS Series and MIN Series Devices
43RIESGO
abrir ↗Nucleimedium
Mailpit < 1.28.2 - SMTP CRLF Injection
Mailpit has SMTP Header Injection via Regex Bypass
28RIESGO
abrir ↗Nucleihigh
ProFTPD mod_sql - Preauth User Backdoor
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
36RIESGO
abrir ↗Nucleicritical
ProFTPd-1.3.3c - Backdoor Command Execution
ProFTPD 1.3.3c Backdoor Command Execution
63RIESGO
abrir ↗Nucleimedium
MySQL - Authentication Bypass
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir ↗Nucleihigh
Memcached Server SASL Authentication - Remote Code Execution
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of
48RIESGO
abrir ↗Nucleicritical
Cisco Smart Install - Configuration Download
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica
100RIESGO
abrir ↗Nucleihigh
Apache HTTP Server - NULL Pointer Dereference
mod_md, DoS via Coredumps on specially crafted requests
30RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.