Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8182Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4217 exploits
Nucleihigh
WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injection
Arbitrary SQL (SQL injection) possible via the Store API component.
61RIESGO
abrir ↗Nucleihigh
TermTalk Server 3.24.0.2 - Local File Inclusion
A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthe
50RIESGO
abrir ↗Nucleicritical
RealTek Jungle SDK - Arbitrary Command Injection
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be u
95RIESGO
abrir ↗Nucleicritical
ForgeRock OpenAM <7.0 - Remote Code Execution
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir ↗Nucleimedium
Thruk 2.40-2 - Cross-Site Scripting
Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title paramete
18RIESGO
abrir ↗Nucleicritical
Oracle Access Manager - Remote Code Execution
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
95RIESGO
abrir ↗Nucleihigh
Motorola Baby Monitors - Remote Command Execution
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras tha
48RIESGO
abrir ↗Nucleicritical
Hikvision IP camera/NVR - Remote Command Execution
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗Nucleicritical
Kramer VIAware - Remote Code Execution
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa
50RIESGO
abrir ↗Nucleicritical
Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dns
95RIESGO
abrir ↗Nucleimedium
Verint Workforce Optimization 15.2.8.10048 - Cross-Site Scripting
Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.
30RIESGO
abrir ↗Nucleimedium
Nova noVNC - Open Redirect
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to
23RIESGO
abrir ↗Nucleimedium
IceWarp Mail Server - Open Redirect
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the refere
18RIESGO
abrir ↗Nucleimedium
KodExplorer - Cross-Site Scripting
A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.
18RIESGO
abrir ↗Nucleihigh
PrestaHome Blog for PrestaShop <1.7.8 - SQL Injection
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestash
23RIESGO
abrir ↗Nucleimedium
Apache Druid - Local File Inclusion
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
60RIESGO
abrir ↗Nucleimedium
WordPress iQ Block Country <=1.2.11 - Cross-Site Scripting
WordPress iQ Block Country plugin <= 1.2.11 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
28RIESGO
abrir ↗Nucleicritical
WordPress Image Hover Ultimate - Unauthenticated Settings Update
WordPress Image Hover Effects Ultimate plugin <= 9.6.1 - Unauthenticated Arbitrary Options Update leading to full website compromise
43RIESGO
abrir ↗Nucleimedium
QSAN Storage Manager <3.3.3 - Cross-Site Scripting
QSAN Storage Manager - Reflected Cross-Site Scripting
28RIESGO
abrir ↗Nucleicritical
KevinLAB BEMS 1.0 - SQL Injection
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id
18RIESGO
abrir ↗Nucleihigh
KevinLAB BEMS (Building Energy Management System) - Backdoor Account
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocu
18RIESGO
abrir ↗Nucleihigh
Jeecg Boot <= 2.4.5 - Information Disclosure
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege an
36RIESGO
abrir ↗Nucleihigh
Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and vi
36RIESGO
abrir ↗Nucleicritical
Zoho ManageEngine ServiceDesk Plus - Authentication Bypass
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs w
95RIESGO
abrir ↗Nucleimedium
Zoho ManageEngine ADSelfService Plus <=6103 - Cross-Site Scripting
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
18RIESGO
abrir ↗Nucleicritical
PrestaShop SmartBlog <4.0.6 - SQL Injection
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthentica
40RIESGO
abrir ↗Nucleimedium
Tiny Java Web Server - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS
18RIESGO
abrir ↗Nucleicritical
Apache ShenYu Admin JWT - Authentication Bypass
Apache ShenYu Admin bypass JWT authentication
50RIESGO
abrir ↗Nucleihigh
Virtua Software Cobranca <12R - Blind SQL Injection
Virtua Cobranca before 12R allows SQL Injection on the login page.
43RIESGO
abrir ↗Nucleimedium
WP Cerber < 8.9.3 - Broken Access Control
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
18RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.