Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Dell KACE K1000 File Upload
Dell/Quest KACE K1000 Unauthenticated File Upload RCE
43RIESGO
abrir ↗Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RIESGO
abrir ↗Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir ↗Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RIESGO
abrir ↗Metasploit0
Vtiger Install Unauthenticated Remote Command Execution
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RIESGO
abrir ↗Metasploit300
Joomla weblinks-categories Unauthenticated SQL Injection Arbitrary File Read
SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL
18RIESGO
abrir ↗Metasploit300
Oracle Demantra Database Credentials Leak
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir ↗Metasploit300
Oracle Demantra Arbitrary File Retrieval with Authentication Bypass
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir ↗Metasploit300
Oracle Demantra Database Credentials Leak
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir ↗Metasploit300
Oracle Demantra Arbitrary File Retrieval with Authentication Bypass
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir ↗Metasploit300
MantisBT Admin SQL Injection Arbitrary File Read
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 a
23RIESGO
abrir ↗Metasploit300
JIRA Issues Collector Directory Traversal
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers t
43RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager /servlet/ConsoleServlet Remote Command Execution
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager /servlet/ConsoleServlet Remote Command Execution
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RIESGO
abrir ↗Metasploit400
SolidWorks Workgroup PDM 2014 pdmwService.exe Arbitrary File Write
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RIESGO
abrir ↗Metasploit300
Linksys WRT120N tmUnblock Stack Buffer Overflow
Linksys WRT120N tmUnblock.cgi Stack-Based Buffer Overflow Admin Password Reset
28RIESGO
abrir ↗Metasploit600
Linksys E-Series TheMoon Remote Command Injection
Linksys Routers E/WAG/WAP/WES/WET/WRT-Series
85RIESGO
abrir ↗Metasploit300
MS14-012 Microsoft Internet Explorer CMarkup Use-After-Free
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RIESGO
abrir ↗Metasploit600
Fritz!Box Webcm Unauthenticated Command Injection
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter t
60RIESGO
abrir ↗Metasploit500
MS14-009 .NET Deployment Service IE Sandbox Escape
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it
50RIESGO
abrir ↗Metasploit300
Apache Commons FileUpload and Apache Tomcat DoS
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RIESGO
abrir ↗Metasploit300
Adobe Flash Player Integer Underflow Remote Code Execution
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Ma
100RIESGO
abrir ↗Metasploit300
Publish-It PUI Buffer Overflow (SEH)
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir ↗Metasploit600
Array Networks vAPV and vxAG Private Key Privilege Escalation Code Execution
Array Networks vAPV and vxAG Default Credential Privilege Escalation
43RIESGO
abrir ↗Metasploit400
Linux Kernel recvmmsg Privilege Escalation
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir ↗Metasploit600
Pandora FMS Default Credential / SQLi Remote Code Execution
Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE
63RIESGO
abrir ↗Metasploit600
Zpanel Remote Unauthenticated RCE
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir ↗Metasploit600
Pandora FMS Remote Code Execution
Pandora FMS <= 5.0RC1 Anyterm Unauthenticated Command Injection
63RIESGO
abrir ↗Metasploit600
MediaWiki Thumb.php Remote Command Execution
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir ↗Metasploit300
A10 Networks AX Loadbalancer Directory Traversal
A10 Networks AX Loadbalancer Path Traversal
36RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.