Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleicritical
Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE
CVE-2026-35273CRITICALbajo ataqueransomware
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
100RIESGO
abrir
Nucleihigh
FortiClient EMS - Authentication Bypass
CVE-2026-35616CRITICALbajo ataque
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RIESGO
abrir
Nucleicritical
WordPress Kali Forms <= 2.4.9 - Remote Code Execution
Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
63RIESGO
abrir
Nucleicritical
dash-uploader 0.1.0 - 0.7.0a2 - Unauthenticated Arbitrary File Write via Path Traversal
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut
43RIESGO
abrir
Nucleihigh
dash-uploader 0.1.0 - 0.7.0a2 - Denial-of-Service via flowTotalChunks
Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-u
36RIESGO
abrir
Nucleicritical
Breeze <= 2.4.4 - Arbitrary File Upload
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
75RIESGO
abrir
Nucleicritical
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
43RIESGO
abrir
Nucleicritical
ChurchCRM - API Authentication Bypass via URL Injection
ChurchCRM has an API Authentication Bypass
43RIESGO
abrir
Nucleimedium
Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversal
Frappe has an Arbitrary File Read via Path Traversal in render_include
36RIESGO
abrir
Nucleihigh
Vite Dev Server - Directory Traversal
Vite has a `server.fs.deny` bypass with queries
36RIESGO
abrir
Nucleimedium
Vite Dev Server - Path Traversal in Optimized Deps .map Handling
Vite has a Path Traversal in Optimized Deps `.map` Handling
28RIESGO
abrir
Nucleicritical
Fortinet FortiSandbox - Command Injection
CVE-2026-39808CRITICALbajo ataque
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RIESGO
abrir
Nucleimedium
XWiki - Cross-Site Scripting
XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality
28RIESGO
abrir
Nucleimedium
PraisonAI AgentOS - Information Disclosure
PraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
28RIESGO
abrir
Nucleihigh
Gravity SMTP WordPress Plugin - Sensitive Information Exposure
Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API
68RIESGO
abrir
Nucleihigh
Arcane <= 1.17.2 - Server-Side Request Forgery
Arcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
36RIESGO
abrir
Nucleicritical
WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection
ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter
36RIESGO
abrir
Nucleicritical
Check Point IKEv1 Remote-Access VPN - Certificate Authentication Bypass
CVE-2026-50751CRITICALbajo ataqueransomware
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir
Nucleilow
Gogs < 0.14.3 - Unauthenticated Organization Teams Disclosure
Gogs: Unauthenticated Organization Teams Information Disclosure via API
28RIESGO
abrir
Nucleicritical
Magento 2 Amasty Order Attributes < 4.0.0 - Unauthenticated Arbitrary File Upload
Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
63RIESGO
abrir
Nucleihigh
SiYuan <= 3.6.5 - Unauthenticated Path Traversal
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
36RIESGO
abrir
Nucleihigh
SiYuan Note <= 3.6.5 - Authentication Bypass
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
43RIESGO
abrir
Nucleimedium
LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
43RIESGO
abrir
Nucleimedium
vLLM <= 0.23.0 - Anthropic Router Heap Address Information Leak
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
28RIESGO
abrir
Nucleicritical
YMC Filter - SQL Injection
WordPress Filter & Grids plugin <= 3.11.5 - SQL Injection vulnerability
43RIESGO
abrir
Nucleimedium
Dashy <= 4.3.6 - Reflected XSS via Workspace
Dashy: XSS in workspace url parameter
23RIESGO
abrir
Nucleimedium
VvvebJs <= 2.0.5 - Cross-Site Scripting
givanz Vvvebjs File Upload Endpoint upload.php cross site scripting
48RIESGO
abrir
Nucleicritical
Page Builder CK <= 3.5.10 - Unauthenticated Arbitrary File Upload
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
68RIESGO
abrir
Nucleicritical
Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
CVE-2026-56291CRITICALbajo ataque
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
93RIESGO
abrir
Nucleicritical
Gorse < 0.5.10 - Unauthenticated Database Dump
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RIESGO
abrir
anteriorpágina 100 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.