Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.939exploits catalogados
32.191CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.295VulnCheck XDB 8176Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleihigh
Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints
WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability
63RIESGO
abrir ↗Nucleimedium
EventON Lite < 2.1.2 - Arbitrary File Download
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RIESGO
abrir ↗Nucleihigh
Ghost CMS < 5.42.1 - Path Traversal
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RIESGO
abrir ↗Nucleicritical
WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir ↗Nucleihigh
Openfire Administration Console - Authentication Bypass
Openfire administration console authentication bypass
100RIESGO
abrir ↗Nucleicritical
Ivanti Avalanche - Remote Code Execution
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
58RIESGO
abrir ↗Nucleicritical
Subscribe to Category <= 2.7.4 - SQL Injection
WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to SQL Injection
63RIESGO
abrir ↗Nucleicritical
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
43RIESGO
abrir ↗Nucleicritical
Emby Server - Authentication Bypass
Emby Server Proxy Header Spoofing Vulnerability
43RIESGO
abrir ↗Nucleicritical
Old Age Home Management System v1.0 - SQL Injection
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
43RIESGO
abrir ↗Nucleimedium
BlogEngine CMS - Open Redirect
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
40RIESGO
abrir ↗Nucleihigh
Faculty Evaluation System v1.0 - SQL Injection
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=.
36RIESGO
abrir ↗Nucleihigh
Faculty Evaluation System v1.0 - Remote Code Execution
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u
61RIESGO
abrir ↗Nucleimedium
LMS by Masteriyo < 1.6.8 - Information Exposure
LMS by Masteriyo < 1.6.8 - Information Exposure
18RIESGO
abrir ↗Nucleihigh
Jeecg P3 Biz Chat - Local File Inclusion
Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
36RIESGO
abrir ↗Nucleihigh
Dolibarr Unauthenticated Contacts Database Theft
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's
23RIESGO
abrir ↗Nucleihigh
H3C Magic R300-2100M - Remote Code Execution
H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at
36RIESGO
abrir ↗Nucleicritical
Chamilo LMS <= v1.11.20 Unauthenticated Command Injection
Chamilo LMS Unauthenticated Command Injection
55RIESGO
abrir ↗Nucleicritical
WAVLINK WN579X3 - Remote Command Execution
Wavlink WN579X3 Ping Test adm.cgi injection
28RIESGO
abrir ↗Nucleicritical
FUXA - Unauthenticated Remote Code Execution
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute
43RIESGO
abrir ↗Nucleihigh
Beautiful Cookie Consent Banner < 2.10.2 - Cross-Site Scripting
Beautiful Cookie Consent Banner <= 2.10.1 - Unauthenticated Stored Cross-Site Scripting
58RIESGO
abrir ↗Nucleimedium
OpenProject < 12.5.4 - Project Identifiers Exposure
OpenProject vulnerable to project identifier information leakage through robots.txt
36RIESGO
abrir ↗Nucleimedium
Uncanny Toolkit for LearnDash - Open Redirection
WordPress Uncanny Toolkit for LearnDash plugin <= 3.6.4.3 - Open Redirection vulnerability
28RIESGO
abrir ↗Nucleicritical
VMware vCenter Server - Out-of-Bounds Write
VMware vCenter Server Out-of-Bounds Write Vulnerability
95RIESGO
abrir ↗Nucleihigh
Vite Dev Server - Information Exposure
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
36RIESGO
abrir ↗Nucleihigh
SRS - Command Injection
SRS has command injection vulnerability in demonstration api-server for HTTP callback.
36RIESGO
abrir ↗Nucleicritical
SonicWall GMS and Analytics Web Services - Shell Injection
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
75RIESGO
abrir ↗Nucleihigh
SonicWall GMS and Analytics - SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and
58RIESGO
abrir ↗Nucleicritical
Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scripting
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary co
95RIESGO
abrir ↗Nucleimedium
Kyocera TASKalfa printer - Path Traversal
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read ar
40RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.