Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3489 exploits
Metasploit300
ThinManager Path Traversal (CVE-2023-27856) Arbitrary File Download
Rockwell Automation ThinManager ThinServer Path Traversal Download
58RIESGO
abrir ↗Metasploit300
ThinManager Path Traversal (CVE-2023-27855) Arbitrary File Upload
Rockwell Automation ThinManager ThinServer Path Traversal Upload
48RIESGO
abrir ↗Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RIESGO
abrir ↗Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RIESGO
abrir ↗Metasploit500
Zyxel IKE Packet Decoder Unauthenticated Remote Code Execution
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir ↗Metasploit600
Nextcloud Workflows Remote Code Execution
Scope of workflow operations is not validated in nextcloud server
63RIESGO
abrir ↗Metasploit600
Rocket Software Unidata udadmin_server Authentication Bypass
Authentication bypass in UniRPC's udadmin service
75RIESGO
abrir ↗Metasploit400
Rocket Software Unidata udadmin_server Stack Buffer Overflow in Password
Stack buffer overflow in UniRPC's udadmin_server service
75RIESGO
abrir ↗Metasploit300
Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RIESGO
abrir ↗Metasploit600
Local Privilege Escalation via CVE-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗Metasploit300
MinIO Bootstrap Verify Information Disclosure
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir ↗Metasploit600
pfSense Restore RRD Data Command Injection
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attac
60RIESGO
abrir ↗Metasploit300
Dolibarr 16 pre-auth contact database dump
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's
23RIESGO
abrir ↗Metasploit600
Adobe ColdFusion Unauthenticated Remote Code Execution
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir ↗Metasploit600
PaperCut PaperCutNG Authentication Bypass
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗Metasploit600
Lexmark Device Embedded Web Server RCE
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
68RIESGO
abrir ↗Metasploit600
Pretalx Limited File Write to Remote Code Execution
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RIESGO
abrir ↗Metasploit300
Pretalx Arbitrary File Read/Limited File Write
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload craft
28RIESGO
abrir ↗Metasploit300
Pretalx Arbitrary File Read/Limited File Write
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RIESGO
abrir ↗Metasploit600
SPIP form PHP Injection
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗Metasploit600
ZoneMinder Snapshots Command Injection
ZoneMinder vulnerable to Missing Authorization
58RIESGO
abrir ↗Metasploit300
RPyC 4.1.0 through 4.1.1 Remote Command Execution
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure
23RIESGO
abrir ↗Metasploit600
Fortinet FortiNAC keyUpload.jsp arbitrary file write
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RIESGO
abrir ↗Metasploit600
Lucee Authenticated Scheduled Job Code Execution
Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
63RIESGO
abrir ↗Metasploit600
Apache Druid JNDI Injection RCE
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RIESGO
abrir ↗Metasploit300
Joomla API Improper Access Checks
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗Metasploit600
Fortra GoAnywhere MFT Unsafe Deserialization RCE
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RIESGO
abrir ↗Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
85RIESGO
abrir ↗Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sen
53RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.