Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleihigh
SureTriggers – All-in-One Automation Platform ≤ 1.0.78 - Authentication Bypass
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RIESGO
abrir ↗Nucleimedium
Vite Development Server - Path Traversal
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir ↗Nucleihigh
Yeswiki < 4.5.2 - Unauthenticated Path Traversal
Path Traversal allowing arbitrary read of files in Yeswiki
56RIESGO
abrir ↗Nucleihigh
React Server Components - Denial of Service
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1
68RIESGO
abrir ↗Nucleicritical
ArgoCD Project API Token Repository Credentials Exposure
Argo CD: Project API Token Exposes Repository Credentials
43RIESGO
abrir ↗Nucleimedium
Astro - Unauthorized Third-Party Image Access
Unauthorized third-party images in Astro’s _image endpoint
28RIESGO
abrir ↗Nucleihigh
Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory tr
23RIESGO
abrir ↗Nucleihigh
XWiki Platform - Information Disclosure
XWiki Platform's configuration files can be accessed through the webjars API
43RIESGO
abrir ↗Nucleihigh
XWiki Platform - Path Traversal
XWiki Platform's configuration files can be accessed through jsx and sx endpoints
43RIESGO
abrir ↗Nucleihigh
XWiki - Information Disclosure
The XWiki Jetty package (XJetty) allows accessing any application file through URL
36RIESGO
abrir ↗Nucleimedium
WSO2 Management Console - Authentication Bypass
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
28RIESGO
abrir ↗Nucleihigh
LiquidFiles < 4.2 - User Enumeration via Password Reset
LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The appli
56RIESGO
abrir ↗Nucleimedium
Avigilon ACM - Host Header Injection
A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplyin
43RIESGO
abrir ↗Nucleihigh
Dify v1.6.0 - Server-Side Request Forgery
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_
28RIESGO
abrir ↗Nucleicritical
Datart v1.0.0-rc.3 - Remote Code Execution
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
63RIESGO
abrir ↗Nucleicritical
HyperComments <= 1.2.2 - Arbitrary Options Update
HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update
36RIESGO
abrir ↗Nucleicritical
Citrix NetScaler Memory Disclosure - CitrixBleed 2
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗Nucleimedium
Commvault Unauthenticated Password Disclosure (WT-2025-0047)
Unauthorized API Access Risk
28RIESGO
abrir ↗Nucleimedium
Commvault Initial Administrator Login Process Vulnerability
Vulnerability in Initial Administrator Login Process
28RIESGO
abrir ↗Nucleihigh
ESPHome - Authentication Bypass
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
36RIESGO
abrir ↗Nucleicritical
FreePBX - Remote Code Execution
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗Nucleimedium
Next.js Middleware - Server-Side Request Forgery
Next.js Improper Middleware Redirect Handling Leads to SSRF
28RIESGO
abrir ↗Nucleimedium
JumpServer - Open Redirect via Referer Header
JumpServer has an Open Redirect Vulnerability
28RIESGO
abrir ↗Nucleihigh
Astro Cloudflare Adapter - Server Side Request Forgery
Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint
36RIESGO
abrir ↗Nucleimedium
WordPress 3D FlipBook Plugin <= 1.16.17 - Sensitive Information Exposure
WordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure Vulnerability
28RIESGO
abrir ↗Nucleihigh
GeoServer - XML External Entity Injection
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir ↗Nucleicritical
Flowise <= 3.0.5 - Account Takeover
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir ↗Nucleicritical
FOGProject <= 1.5.10.1673 - Authentication Bypass
FOG's authentication bypass leads to full SQL DB dump
68RIESGO
abrir ↗Nucleilow
Vite Dev Server - Path Traversal
Vite middleware may serve files starting with the same name with the public directory
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.