Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleicritical
Langflow AI <= 1.6.9 - CORS Misconfiguration
CVE-2025-34291CRITICALbajo ataque
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
100RIESGO
abrir
Nucleicritical
Monsta FTP <= 2.11.2 - Unauthenticated Remote Code Execution
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir
Nucleicritical
SawtoothSoftware Lighthouse Studio < 9.16.14 - Pre-Auth Remote Code Execution
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RIESGO
abrir
Nucleihigh
Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials
Sitecore XM and XP Hardcoded Credentials
48RIESGO
abrir
Nucleimedium
Ocean Extra <= 2.4.6 - Unauthenticated Shortcode Execution
Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution
28RIESGO
abrir
Nucleihigh
Contact Form 7 Drag and Drop Multiple File Upload - Arbitrary File Upload
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RIESGO
abrir
Nucleicritical
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RIESGO
abrir
Nucleicritical
Dell UnityVSA < 5.5 - Remote Command Injection
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('
68RIESGO
abrir
Nucleihigh
Eveo URVE Web Manager - Server-Side Request Forgery
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side
36RIESGO
abrir
Nucleicritical
HPE OneView - Remote Code Execution
CVE-2025-37164CRITICALbajo ataque
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir
Nucleihigh
Personal Weather Station Dashboard 12 - Directory Traversal
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ direct
28RIESGO
abrir
Nucleihigh
WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download
WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
36RIESGO
abrir
Nucleicritical
Eventin <= 4.0.26 - Privilege Escalation
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RIESGO
abrir
Nucleihigh
TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Upload
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RIESGO
abrir
Nucleicritical
PSW Front-end Login & Registration 1.13 - Weak Password Recovery
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RIESGO
abrir
Nucleimedium
Label Studio < 1.18.0 - Reflected XSS
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
36RIESGO
abrir
Nucleicritical
Wing FTP Server <= 7.4.3 - Remote Code Execution
CVE-2025-47812CRITICALbajo ataque
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
Nucleimedium
Wing FTP Server <= 7.4.3 - Path Disclosure via Overlong UID Cookie
CVE-2025-47813MEDIUMbajo ataque
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
70RIESGO
abrir
Nucleicritical
Invision Community <=5.0.6 Unauthenticated RCE via Template Injection
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RIESGO
abrir
Nucleicritical
WordPress Formality Plugin <= 1.5.9 - Local File Inclusion
WordPress Formality <= 1.5.9 - Local File Inclusion Vulnerability
36RIESGO
abrir
Nucleicritical
MyStyle Custom Product Designer <= 3.21.1 - SQL Injection
WordPress MyStyle Custom Product Designer plugin <= 3.21.1 - SQL Injection Vulnerability
43RIESGO
abrir
Nucleicritical
CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Execution
CVE-2025-48703CRITICALbajo ataque
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RIESGO
abrir
Nucleicritical
vBulletin 5.0.0-6.0.3 - Authentication Bypass
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
Nucleicritical
vBulletin replaceAdTemplate - Remote Code Execution
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RIESGO
abrir
Nucleihigh
Discourse OAuth Social Login - Cross-site Scripting
Discourse vulnerable to XSS via user-provided query parameter in oauth failure flow
36RIESGO
abrir
Nucleicritical
DataEase < 2.10.10 - JWT Authentication Bypass
Dataease Authentication Bypass Vulnerability
41RIESGO
abrir
Nucleihigh
DataEase - Remote Code Execution
Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability
48RIESGO
abrir
Nucleihigh
WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution
WordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
63RIESGO
abrir
Nucleicritical
Roundcube Webmail - Remote Code Execution
CVE-2025-49113CRITICALbajo ataque
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
Nucleicritical
Pterodactyl Panel - Remote Code Execution
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir
anteriorpágina 120 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.