Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.984exploits catalogados
32.217CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.313VulnCheck XDB 8182Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
4217 exploits
Nucleimedium
Apache Tomcat - HTTP Request Smuggling
Apache Tomcat: Trailer header parsing too lenient
28RIESGO
abrir ↗Nucleimedium
Frigate < 0.13.0 Beta 3 - Cross-Site Scripting
Frigate reflected XSS through `/<camera_name>` API endpoints
28RIESGO
abrir ↗Nucleimedium
PaperCut NG Unauthenticated XMLRPC Functionality
PaperCut NG Unauthenticated XMLRPC
28RIESGO
abrir ↗Nucleimedium
Leantime < 2.4 - Authenticated SQL Injection
Authenticated SQL Injection in leantime
28RIESGO
abrir ↗Nucleicritical
Viessmann Vitogate 300 - Remote Code Execution
In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute a
23RIESGO
abrir ↗Nucleihigh
qdPM 9.2 - Directory Traversal
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
18RIESGO
abrir ↗Nucleicritical
Gibbon LMS <= v25.0.01 - File Upload to RCE
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RIESGO
abrir ↗Nucleicritical
WordPress Plugin Forminator 1.24.6 - Arbitrary File Upload
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗Nucleicritical
Media Library Assistant < 3.09 - Remote Code Execution/Local File Inclusion
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
85RIESGO
abrir ↗Nucleicritical
PrestaShop Step by Step products Pack - SQL Injection
In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a
55RIESGO
abrir ↗Nucleicritical
cPH2 Charging Station v1.87.0 - OS Command Injection
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthen
65RIESGO
abrir ↗Nucleihigh
GL.iNet <= 4.3.7 - Arbitrary File Write
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attac
30RIESGO
abrir ↗Nucleicritical
TOTOLINK A3700R - Command Injection
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName p
30RIESGO
abrir ↗Nucleicritical
Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload
Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗Nucleimedium
XWiki < 14.10.14 - Cross-Site Scripting
Reflected Cross-site scripting through revision parameter in content menu in XWiki Platform
43RIESGO
abrir ↗Nucleicritical
F5 BIG-IP - Unauthenticated RCE via AJP Smuggling
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir ↗Nucleihigh
Ivanti ICS - Authentication Bypass
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RIESGO
abrir ↗Nucleihigh
ISPConfig - PHP Code Injection
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by
41RIESGO
abrir ↗Nucleihigh
Chaosblade < 1.7.4 - Remote Code Execution
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd p
36RIESGO
abrir ↗Nucleihigh
Label Studio - Cross-Site Scripting
Label Studio XSS Vulnerability on Avatar Upload
36RIESGO
abrir ↗Nucleihigh
Label Studio - Sensitive Information Exposure
Object Relational Mapper Leak Vulnerability in Filtering Task in Label Studio
36RIESGO
abrir ↗Nucleihigh
PlayTube 3.0.1 - Information Disclosure
PlayTube Redirect information disclosure
28RIESGO
abrir ↗Nucleihigh
ManageEngine OpManager - Directory Traversal
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A speciall
55RIESGO
abrir ↗Nucleicritical
SysAid Server - Remote Code Execution
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a f
100RIESGO
abrir ↗Nucleicritical
PyArrow Flight RPC - Remote Code Execution
PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file
23RIESGO
abrir ↗Nucleicritical
Qualitor <= 8.20 - Remote Code Execution
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RIESGO
abrir ↗Nucleimedium
SuiteCRM Unauthenticated Graphql Introspection
SuiteCRM has Unauthenticated Graphql Introspection Enabled
23RIESGO
abrir ↗Nucleimedium
Essential Grid <= 3.1.0 - Cross-Site Scripting
WordPress Essential Grid Plugin <= 3.1.0 is vulnerable to Cross Site Scripting (XSS)
36RIESGO
abrir ↗Nucleicritical
WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload
WordPress WP Child Theme Generator plugin <= 1.0.9 - Arbitrary File Upload vulnerability
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.