Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4193 exploits
Nucleicritical
Apache ActiveMQ - Remote Code Execution
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗Nucleimedium
OpenSSH Terrapin Attack - Detection
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot
50RIESGO
abrir ↗Nucleihigh
Jenkins < 2.441 - Arbitrary File Read
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗Nucleicritical
Zimbra Collaboration Suite < 9.0.0 - Remote Code Execution
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir ↗Nucleihigh
CUPS - Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir ↗Nucleimedium
Citrix NetScaler ADC & Gateway - Reflected XSS / Open Redirect
Cross-Site Scripting (XSS)
33RIESGO
abrir ↗Nucleihigh
MongoDB Server - Information Disclosure (MongoBleed)
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗Nucleihigh
D-Link DIR-823X set_prohibiting - Command Injection
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrar
88RIESGO
abrir ↗Nucleicritical
Redis < 8.2.1 lua script - Integer Overflow
Lua library commands may lead to integer overflow and potential RCE
36RIESGO
abrir ↗Nucleihigh
Redis Lua Sandbox < 8.2.2 - Cross-User Escape
Redis: Authenticated users can execute LUA scripts as a different user
28RIESGO
abrir ↗Nucleihigh
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read
Redis is vulnerable to DoS via specially crafted LUA scripts
28RIESGO
abrir ↗Nucleicritical
Redis Lua Parser < 8.2.2 - Use After Free
Redis Lua Use-After-Free may lead to remote code execution
85RIESGO
abrir ↗Nucleicritical
Palo Alto Networks PAN-OS - Authentication Bypass
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir ↗Nucleicritical
BeyondTrust Remote Support - Unauthenticated WebSocket RCE
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir ↗Nucleicritical
Apache Camel camel-coap - Remote Code Execution
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
63RIESGO
abrir ↗Nucleihigh
Vite Dev Server - Arbitrary File Read
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
36RIESGO
abrir ↗Nucleicritical
Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir ↗Nucleihigh
Next.js WebSocket Upgrade Handler - SSRF
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RIESGO
abrir ↗Nucleicritical
Samba Printing Subsystem - Remote Code Execution
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir ↗Nucleimedium
OpenVPN Access Server 2.1.4 - CRLF Injection
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbit
18RIESGO
abrir ↗Nucleimedium
Odoo <= 8.0-20160726 & 9.0 - Open Redirect
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive in
18RIESGO
abrir ↗Nucleihigh
Kodi 17.1 - Local File Inclusion
Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files v
40RIESGO
abrir ↗Nucleicritical
JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer,
23RIESGO
abrir ↗Nucleihigh
PhpColl 2.5.1 Arbitrary File Upload
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RIESGO
abrir ↗Nucleimedium
MaNGOSWebV4 < 4.0.8 - Cross-Site Scripting
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
38RIESGO
abrir ↗Nucleicritical
Windows Server 2003 & IIS 6.0 - Remote Code Execution
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗Nucleimedium
Magmi 0.7.22 - Cross-Site Scripting
A Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The vulnerability exists due to insufficient filtration o
18RIESGO
abrir ↗Nucleihigh
MantisBT <=2.30 - Arbitrary Password Reset/Admin Access
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RIESGO
abrir ↗Nucleimedium
IceWarp WebMail 11.3.1.5 - Cross-Site Scripting
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" paramet
18RIESGO
abrir ↗Nucleicritical
Hikvision - Authentication Bypass
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.