Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8182Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4217 exploits
Nucleicritical
NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Execution
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RIESGO
abrir ↗Nucleihigh
Yeti Platform < 2.1.12 - Server-Side Template Injection to RCE
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor
56RIESGO
abrir ↗Nucleicritical
DATAGERRY - REST API Auth Bypass
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
63RIESGO
abrir ↗Nucleihigh
Sitecore Experience Platform <= 10.4 - Arbitrary File Read
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0
48RIESGO
abrir ↗Nucleicritical
Camaleon CMS < 2.8.1 Arbitrary File Write to RCE
Arbitrary file write leading to RCE in Camaleon CMS
75RIESGO
abrir ↗Nucleicritical
Navidrome < 0.53.0 - Authenticated SQL Injection
Multiple SQL Injections and ORM Leak in navidrome
63RIESGO
abrir ↗Nucleicritical
DataEase v2.10.2 - JWT Signature Verification Bypass
Dataease arbitrary interface access vulnerability
43RIESGO
abrir ↗Nucleimedium
Templately <= 3.1.2 - Broken Access Control
WordPress Templately plugin <= 3.1.2 - Broken Access Control vulnerability
28RIESGO
abrir ↗Nucleihigh
LiteSpeed Cache <= 6.5.0.2 - Stored XSS
WordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
36RIESGO
abrir ↗Nucleicritical
Cobbler 'XML-RPC' - Authentication Bypass
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RIESGO
abrir ↗Nucleihigh
NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Read
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RIESGO
abrir ↗Nucleicritical
Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injection
SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
65RIESGO
abrir ↗Nucleimedium
Ganglia Web Interface (v3.7.3 - v3.7.6) - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows atta
28RIESGO
abrir ↗Nucleimedium
Ganglia Web Interface (v3.7.3 - v3.7.5) - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows
28RIESGO
abrir ↗Nucleihigh
Kerio Control v9.2.5 - CRLF Injection
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertE
41RIESGO
abrir ↗Nucleicritical
Dolibarr ERP CMS `list.php` - SQL Injection
Multiple vulnerabilities in DOLIBARR's ERP CMS
55RIESGO
abrir ↗Nucleimedium
WordPress Events Calendar 6.8.2.1 - Information Disclosure
The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure
28RIESGO
abrir ↗Nucleicritical
SSL VPN Session Hijacking
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir ↗Nucleicritical
Mongoose < 8.8.3 - Remote Code Execution
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir ↗Nucleihigh
Discourse Backup File Disclosure Via Default Nginx Configuration
Potential Backup file leaked via Nginx in Discourse
41RIESGO
abrir ↗Nucleihigh
SEH utnserver Pro/ProMAX/INU-100 20.1.22 - Cross-Site Scripting
Stored Cross-Site Scripting in SEH Computertechnik utnserver Pro
36RIESGO
abrir ↗Nucleihigh
SEH utnserver Pro/ProMAX/INU-100 20.1.22 - File Exposure
Authenticated Command Injection
36RIESGO
abrir ↗Nucleihigh
Hurrakify <= 2.4 - Server-Side Request Forgery
WordPress Hurrakify plugin <= 2.4 - Server Side Request Forgery (SSRF) vulnerability
36RIESGO
abrir ↗Nucleihigh
Radio Player <= 2.0.82 - Server-Side Request Forgery
WordPress Radio Player plugin <= 2.0.83 - Server Side Request Forgery (SSRF) vulnerability
36RIESGO
abrir ↗Nucleimedium
ipTIME A2004 - Unauthorized Access
An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensiti
28RIESGO
abrir ↗Nucleimedium
ipTIME A2004 - Unauthorized Access
An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensit
28RIESGO
abrir ↗Nucleihigh
AVM FRITZ!Box 7530 AX - Unauthorized Access
An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sen
36RIESGO
abrir ↗Nucleimedium
LearnPress < 4.2.6.8.1 - Information Disclosure
LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.