Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleicritical
Apache OFBiz < 18.12.10 - Arbitrary Code Execution
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir ↗Nucleihigh
OwnCloud - Phpinfo Configuration
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RIESGO
abrir ↗Nucleihigh
Peplink Balance Two before 8.4.0 - Unauthenticated Config Upload
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows att
18RIESGO
abrir ↗Nucleimedium
Vite dev server - Cross-Site Scripting
Cross-site Scripting in `server.transformIndexHtml` via URL payload in vite
28RIESGO
abrir ↗Nucleimedium
Python Flask-Security-Too <=5.3.2 - Open Redirect
An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspectin
18RIESGO
abrir ↗Nucleimedium
KodeExplorer 4.51 - Reflective Cross Site Scripting (XSS)
Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive in
28RIESGO
abrir ↗Nucleimedium
DedeCMS v5.7.111 - Cross-Site Scripting
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component selec
18RIESGO
abrir ↗Nucleihigh
Citrix Bleed - Leaking Session Tokens
Unauthenticated sensitive information disclosure
100RIESGO
abrir ↗Nucleimedium
Academy LMS 6.2 - Cross-Site Scripting
Academy LMS GET Parameter filter cross site scripting
23RIESGO
abrir ↗Nucleicritical
Academy LMS 6.2 - SQL Injection
Academy LMS GET Parameter filter sql injection
28RIESGO
abrir ↗Nucleicritical
ChatGPT-Next-Web - SSRF/XSS
NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting
85RIESGO
abrir ↗Nucleihigh
Active Directory Integration WP Plugin < 4.1.10 - Log Disclosure
Active Directory Integration < 4.1.10 - Unauthenticated Log Disclosure
41RIESGO
abrir ↗Nucleihigh
reNgine 2.2.0 - Command Injection
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacha
41RIESGO
abrir ↗Nucleimedium
Apache Solr - Host Environment Variables Leak via Metrics API
Apache Solr: Host environment variables are published via the Metrics API
40RIESGO
abrir ↗Nucleicritical
Mingsoft MCMS 5.2.9 - SQL Injection
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/
43RIESGO
abrir ↗Nucleihigh
XWiki < 4.10.15 - Sensitive Information Disclosure
XWiki Platform Solr search discloses password hashes of all users
58RIESGO
abrir ↗Nucleimedium
XWiki < 4.10.15 - Email Disclosure
XWiki Platform Solr search discloses email addresses of users
40RIESGO
abrir ↗Nucleicritical
D-Link D-View 8 v2.0.1.28 - Authentication Bypass
Authentication Bypass in D-Link D-View 8
55RIESGO
abrir ↗Nucleicritical
JS Help Desk <= 2.8.1 - SQL Injection
WordPress JS Help Desk – Best Help Desk & Support Plugin <= 2.8.1 is vulnerable to SQL Injection
63RIESGO
abrir ↗Nucleimedium
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
28RIESGO
abrir ↗Nucleicritical
MajorDoMo thumb.php - OS Command Injection
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RIESGO
abrir ↗Nucleihigh
Apache OFBiz < 18.12.11 - Server Side Request Forgery
Apache OFBiz: Arbitrary file properties reading and SSRF attack
30RIESGO
abrir ↗Nucleicritical
Jordy Meow AI Engine - Unrestricted File Upload
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RIESGO
abrir ↗Nucleihigh
Gradio Hugging Face - Local File Inclusion
Make the `/file` secure against file traversal attacks
28RIESGO
abrir ↗Nucleihigh
SolarWinds Security Event Manager - Unauthenticated RCE
SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
78RIESGO
abrir ↗Nucleicritical
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
43RIESGO
abrir ↗Nucleicritical
Arcserve Unified Data Protection - Authentication Bypass
Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
43RIESGO
abrir ↗Nucleihigh
Arcserve Unified Data Protection - Unauthenticated DoS in ASNative.dll
Unauthenticated DoS in Arcserve Unified Data Protection
48RIESGO
abrir ↗Nucleimedium
Combo Blocks < 2.2.76 - Improper Access Control
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.