Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8182Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4217 exploits
Nucleimedium
Dash Framework - Cross-site Scripting
Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; v
28RIESGO
abrir ↗Nucleimedium
Flarum < 1.8.5 - Open Redirect
Flarum's Logout Route allows open redirects
28RIESGO
abrir ↗Nucleihigh
pyLoad Flask Config - Access Control
pyLoad unauthenticated flask configuration leakage
48RIESGO
abrir ↗Nucleicritical
XWiki < 4.10.20 - Remote code execution
XWiki Remote Code Execution vulnerability via user registration
65RIESGO
abrir ↗Nucleicritical
Ivanti EPM - Remote Code Execution
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RIESGO
abrir ↗Nucleicritical
Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RIESGO
abrir ↗Nucleihigh
GLPI 10.0.10-10.0.14 - SQL Injection
GLPI contains an SQL injection through the saved searches
48RIESGO
abrir ↗Nucleicritical
Cacti cmd_realtime.php - Command Injection
Cacti command injection in cmd_realtime.php
85RIESGO
abrir ↗Nucleimedium
WP Go Maps <= 9.0.29 - Cross-Site Scripting
WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability
36RIESGO
abrir ↗Nucleicritical
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RIESGO
abrir ↗Nucleicritical
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command Injection
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir ↗Nucleicritical
IPS Community Suite - Unauthenticated SQL Injection
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\
43RIESGO
abrir ↗Nucleihigh
Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write
Apache DolphinScheduler: Resource File Read And Write Vulnerability
36RIESGO
abrir ↗Nucleimedium
Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting
WordPress Sunshine Photo Cart plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
36RIESGO
abrir ↗Nucleimedium
DataEase <= 2.4.1 - Sensitive Information Exposure
DataEase has database configuration information exposure vulnerability
53RIESGO
abrir ↗Nucleimedium
WordPress Themify Builder < 7.5.8 - Open Redirect
Themify Builder < 7.5.8 - Open Redirect
28RIESGO
abrir ↗Nucleimedium
WPZOOM Social Icons Widget <= 4.2.15 - Missing Authorization
WordPress Social Icons Widget & Block by WPZOOM plugin <= 4.2.15 - Broken Access Control vulnerability
28RIESGO
abrir ↗Nucleicritical
ProfileGrid <= 5.7.8 - SQL Injection
WordPress ProfileGrid plugin <= 5.7.8 - SQL Injection vulnerability
43RIESGO
abrir ↗Nucleicritical
CRM Perks Forms <= 1.1.4 - SQL Injection
WordPress CRM Perks Forms plugin <= 1.1.4 - Unauthenticated SQL Injection vulnerability
43RIESGO
abrir ↗Nucleicritical
WP Travel Engine <= 5.7.9 - SQL Injection
WordPress WP Travel Engine plugin <= 5.7.9 - Unauth. Blind SQL Injection vulnerability
43RIESGO
abrir ↗Nucleicritical
Netgear R6850 V1.1.0.88 - Command Injection
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
55RIESGO
abrir ↗Nucleihigh
Netgear R6850 - Information Disclosure
An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information wi
36RIESGO
abrir ↗Nucleimedium
Netgear R6850 - Information Disclosure
An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without
28RIESGO
abrir ↗Nucleicritical
ASUS DSL-AC88U - Authentication Bypass
ASUS Router - Improper Authentication
55RIESGO
abrir ↗Nucleimedium
NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
40RIESGO
abrir ↗Nucleimedium
Fides Privacy Center ≤ 2.39.1 - Server-Side URL Disclosure
Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
28RIESGO
abrir ↗Nucleicritical
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
43RIESGO
abrir ↗Nucleihigh
Flowise 1.6.5 - Authentication Bypass
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted sc
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.