Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleihigh
Apache Druid - Remote Code Execution
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir ↗Nucleihigh
Hue Magic 3.0.0 - Local File Inclusion
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in fil
18RIESGO
abrir ↗Nucleihigh
Void Aural Rec Monitor 9.0.0.1 - SQL Injection
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a craft
23RIESGO
abrir ↗Nucleimedium
Atlassian Confluence < 5.8.6 - Server-Side Request Forgery
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers
30RIESGO
abrir ↗Nucleicritical
Confluence Server - Remote Code Execution
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗Nucleimedium
Atlassian Confluence Server - Local File Inclusion
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RIESGO
abrir ↗Nucleimedium
Atlassian Jira Limited - Local File Inclusion
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RIESGO
abrir ↗Nucleimedium
Cacti - Cross-Site Scripting
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" t
18RIESGO
abrir ↗Nucleihigh
AfterLogic Aurora and WebMail Pro < 7.7.9 - Information Disclosure
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal
23RIESGO
abrir ↗Nucleicritical
Apache OFBiz <17.12.06 - Arbitrary Code Execution
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RIESGO
abrir ↗Nucleimedium
EPrints 3.4.2 - Cross-Site Scripting
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
18RIESGO
abrir ↗Nucleimedium
ImpressCMS <1.4.3 - Incorrect Authorization
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated atta
23RIESGO
abrir ↗Nucleihigh
ImpressCMS < 1.4.3 - SQL Injection
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
43RIESGO
abrir ↗Nucleimedium
EPrints 3.4.2 - Cross-Site Scripting
EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
18RIESGO
abrir ↗Nucleimedium
Redwood Report2Web 4.3.4.5 & 4.5.3 - Cross-Site Scripting
A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to
18RIESGO
abrir ↗Nucleimedium
Jenzabar 9.2x-9.2.2 - Cross-Site Scripting
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
23RIESGO
abrir ↗Nucleicritical
Apache OFBiz < 17.12.07 - Arbitrary Code Execution
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
30RIESGO
abrir ↗Nucleicritical
HPE Edgeline Infrastructure Manager <1.22 - Authentication Bypass
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infr
30RIESGO
abrir ↗Nucleimedium
Jellyfin 10.7.2 - Server Side Request Forgery
Unauthenticated GET requests through Remote Image endpoints
40RIESGO
abrir ↗Nucleihigh
XStream <1.4.17 - Remote Code Execution
XStream is vulnerable to a Remote Command Execution attack
58RIESGO
abrir ↗Nucleimedium
Seo Panel 4.8.0 - Cross-Site Scripting
Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.
18RIESGO
abrir ↗Nucleimedium
SysAid Technologies 20.3.64 b14 - Cross-Site Scripting
SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.
18RIESGO
abrir ↗Nucleicritical
Laminas Project laminas-http - Remote Code Execution
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead
60RIESGO
abrir ↗Nucleicritical
Kaseya VSA < 9.5.7 - Credential Disclosure via Windows Agent
Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
95RIESGO
abrir ↗Nucleicritical
Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code Execution
Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5
55RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.