Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleimedium
WP MediaTagger <= 4.1.1 - Cross-Site Scripting
WP MediaTagger <= 4.1.1 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WP Projects Portfolio <= 3.0 - Cross-Site Scripting
WP Projects Portfolio with Client Testimonials <= 3.0 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WordPress Download Manager < 3.3.07 - Unauthenticated Data Exposure
Download Manager < 3.3.07 - Unauthenticated Data Exposure
28RIESGO
abrir
Nucleicritical
Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcardRecursive
CVE-2024-13159CRITICALbajo ataque
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir
Nucleicritical
Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcard
CVE-2024-13160CRITICALbajo ataque
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir
Nucleicritical
Ivanti EPM - Credential Coercion Vulnerability in GetHashForSingleFile
CVE-2024-13161CRITICALbajo ataque
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir
Nucleimedium
Privacy Policy Genius - Cross-Site Scripting
Policy Genius <= 2.0.4 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WordPress Google Map Professional - Cross-Site Scripting
Google Map Professional <= 1.0 - Reflected XSS
28RIESGO
abrir
Nucleimedium
Fantastic ElasticSearch Plugin <= 4.1.0 - Cross-Site Scripting
Fantastic Elasticsearch <= 4.1.0 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WordPress User Messages <= 1.2.4 - Reflected XSS
User Messages <= 1.2.4 - Reflected XSS
28RIESGO
abrir
Nucleimedium
SlideDeck 1 Lite Content Slider - Cross-Site Scripting
SlideDeck 1 Lite Content Slider <= 1.4.8 - Reflected XSS
28RIESGO
abrir
Nucleimedium
ECT Home Page Products - Reflected XSS
ECT Home Page Products <= 1.9 - Reflected XSS
28RIESGO
abrir
Nucleimedium
A5 Custom Login Page - Reflected XSS
A5 Custom Login Page <= 2.8.1 - Reflected XSS
28RIESGO
abrir
Nucleihigh
Ads Pro Plugin <= 4.88 - Unauthenticated SQL Injection
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.88 - Unauthenticated SQL Injection
36RIESGO
abrir
Nucleimedium
Glossy WordPress - Reflected XSS
Glossy <= 2.3.5 - Reflected XSS
28RIESGO
abrir
Nucleimedium
iBuildApp <= 0.2.0 - Reflected Cross-Site Scripting
iBuildApp <= 0.2.0 - Reflected XSS
28RIESGO
abrir
Nucleimedium
Musicbox WordPress - Reflected XSS
Musicbox <= 2.0.3 - Reflected XSS
28RIESGO
abrir
Nucleimedium
Giga Messenger WordPress - Cross-Site Scripting
Giga Messenger Bots <= 2.3.1 - Reflected XSS
28RIESGO
abrir
Nucleihigh
JustRows WordPress - Cross-Site Scripting
Justrows Free <= 0.2 - Reflected XSS
36RIESGO
abrir
Nucleimedium
WP Dream Carousel < 1.0.1b - Cross-Site Scripting
WP Dream Carousel <= 1.0.1b - Reflected XSS
28RIESGO
abrir
Nucleihigh
Legull WordPress - Cross-Site Scripting
Legull <= 1.2.2 - Reflected XSS
36RIESGO
abrir
Nucleihigh
Atlassian Confluence Data Center and Server - Remote Code Execution
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RIESGO
abrir
Nucleicritical
Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) - Command Injection
CVE-2024-21887CRITICALbajo ataqueransomware
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir
Nucleihigh
Ivanti SAML - Server Side Request Forgery (SSRF)
CVE-2024-21893HIGHbajo ataqueransomware
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RIESGO
abrir
Nucleihigh
Ivanti Connect Secure - XXE
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Se
78RIESGO
abrir
Nucleimedium
Fastify Swagger-UI - Information Disclosure
Default swagger-ui configuration exposes all files in the module
28RIESGO
abrir
Nucleicritical
IBM Operational Decision Manager - JNDI Injection
IBM Operational Decision Manager JDNI injection
58RIESGO
abrir
Nucleihigh
IBM Operational Decision Manager - Java Deserialization
IBM Operational Decision Manager code execution
65RIESGO
abrir
Nucleicritical
Intel Neural Compressor <2.5.0 - SQL Injection
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated
55RIESGO
abrir
Nucleicritical
Netis MW5360 V1.0.1.3031 - Command Injection
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter
65RIESGO
abrir
anteriorpágina 124 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.