Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleimedium
XWiki - Cross-Site Scripting
XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality
28RIESGO
abrir
Nucleimedium
PraisonAI AgentOS - Information Disclosure
PraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
28RIESGO
abrir
Nucleihigh
Gravity SMTP WordPress Plugin - Sensitive Information Exposure
Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API
68RIESGO
abrir
Nucleihigh
Arcane <= 1.17.2 - Server-Side Request Forgery
Arcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
36RIESGO
abrir
Nucleicritical
WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection
ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter
36RIESGO
abrir
Nucleicritical
Check Point IKEv1 Remote-Access VPN - Certificate Authentication Bypass
CVE-2026-50751CRITICALbajo ataqueransomware
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir
Nucleilow
Gogs < 0.14.3 - Unauthenticated Organization Teams Disclosure
Gogs: Unauthenticated Organization Teams Information Disclosure via API
28RIESGO
abrir
Nucleicritical
Magento 2 Amasty Order Attributes < 4.0.0 - Unauthenticated Arbitrary File Upload
Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
63RIESGO
abrir
Nucleihigh
SiYuan <= 3.6.5 - Unauthenticated Path Traversal
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
36RIESGO
abrir
Nucleihigh
SiYuan Note <= 3.6.5 - Authentication Bypass
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
43RIESGO
abrir
Nucleimedium
LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
43RIESGO
abrir
Nucleimedium
vLLM <= 0.23.0 - Anthropic Router Heap Address Information Leak
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
28RIESGO
abrir
Nucleicritical
YMC Filter - SQL Injection
WordPress Filter & Grids plugin <= 3.11.5 - SQL Injection vulnerability
43RIESGO
abrir
Nucleimedium
Dashy <= 4.3.6 - Reflected XSS via Workspace
Dashy: XSS in workspace url parameter
23RIESGO
abrir
Nucleimedium
VvvebJs <= 2.0.5 - Cross-Site Scripting
givanz Vvvebjs File Upload Endpoint upload.php cross site scripting
48RIESGO
abrir
Nucleicritical
Page Builder CK <= 3.5.10 - Unauthenticated Arbitrary File Upload
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
68RIESGO
abrir
Nucleicritical
Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
CVE-2026-56291CRITICALbajo ataque
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
93RIESGO
abrir
Nucleicritical
Gorse < 0.5.10 - Unauthenticated Database Dump
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RIESGO
abrir
Nucleicritical
Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RIESGO
abrir
Nucleicritical
9Router - Unauthenticated LLM Provider API Exposure
9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
43RIESGO
abrir
Nucleihigh
AstrBot <= 4.22.1 - Command Injection
AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection
48RIESGO
abrir
Nucleimedium
User Registration & Membership WordPress plugin - Open Redirect
User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter
28RIESGO
abrir
Nucleicritical
WordPress Core 6.9-7.0.1 - Pre-Auth Blind SQL Injection (Batch-Route Confusion)
CVE-2026-63030CRITICALbajo ataque
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
Nucleicritical
FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code Execution
Custom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCE
56RIESGO
abrir
Nucleicritical
ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE
Sandbox Escape in ServiceNow AI Platform
63RIESGO
abrir
Nucleimedium
WordPress FluentCRM <= 2.9.87 - Unauthenticated Blind SSRF
FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter
28RIESGO
abrir
Nucleicritical
Progress ADC LoadMaster - Command Injection
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
75RIESGO
abrir
Nucleicritical
dotCMS Core Publish Audit API - Unauthenticated SQL Injection
Unauthenticated SQL Injection in dotCMS Publish Audit API
63RIESGO
abrir
Nucleicritical
WordPress Burst Statistics 3.4.0-3.4.1.1 - Authentication Bypass
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RIESGO
abrir
Nucleimedium
LearnPress < 4.3.7 - Information Disclosure
LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API
48RIESGO
abrir
anteriorpágina 106 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.