Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.995exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.324VulnCheck XDB 8182Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
4217 exploits
Nucleimedium
Dify - User Enumeration via "Account not found" Message
User Enumeration via Distinct Error Messages in langgenius/dify-web
28RIESGO
abrir ↗Nucleicritical
Post SMTP <= 3.6.0 - Email Log Disclosure
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
75RIESGO
abrir ↗Nucleihigh
MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal
Unauthenticated Local File Disclosure in MPDV Mikrolab MIP 2 / FEDRA 2 / HYDRA X Manufacturing Execution System
36RIESGO
abrir ↗Nucleihigh
Integrate Google Drive <= 1.5.3 - Information Disclosure
File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure
36RIESGO
abrir ↗Nucleihigh
Site Reviews < 7.2.5 - Unauthenticated Stored XSS
Site Reviews < 7.2.5 - Unauthenticated Stored XSS
36RIESGO
abrir ↗Nucleicritical
Triofox - Improper Access Control
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to init
95RIESGO
abrir ↗Nucleimedium
SureForms <= 1.13.1 - Sensitive Information Exposure
SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure
28RIESGO
abrir ↗Nucleihigh
WordPress Bookit < 2.5.1 - Unauthenticated Stripe Settings Update
Bookit < 2.5.1 – Unauthenticated Settings Update
28RIESGO
abrir ↗Nucleicritical
JSONPath Plus < 10.3.0 - Remote Code Execution
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RIESGO
abrir ↗Nucleimedium
Plugin Oficial – Getnet para WooCommerce <= 1.8.0 - Cross-Site Scripting
Plugin Oficial – Getnet para WooCommerce <= 1.7.3 - Unauthenticated Reflected XSS
28RIESGO
abrir ↗Nucleihigh
WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection
WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection via select_2_ajax() Function
36RIESGO
abrir ↗Nucleihigh
WP-Recall – Plugin <= 16.26.10 - Unauthenticated SQL Injection
WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection
36RIESGO
abrir ↗Nucleicritical
Twonky Server 8.5.2 on Linux and Windows - Log File Exposure
Unauthenticated log access in Twonky Server
75RIESGO
abrir ↗Nucleihigh
Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read
Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read
36RIESGO
abrir ↗Nucleicritical
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
100RIESGO
abrir ↗Nucleicritical
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006)
Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
100RIESGO
abrir ↗Nucleimedium
Kentico Xperience CMS - Unauthenticated Stored XSS
Kentico Xperience stored cross-site scripting in multiple-file upload functionality
60RIESGO
abrir ↗Nucleimedium
GeoServer - Missing Authorization on REST API Index
GeoServer Missing Authorization on REST API Index
28RIESGO
abrir ↗Nucleimedium
NocoDB < 0.258.0 - Reflected XSS in Password Reset
NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page
28RIESGO
abrir ↗Nucleicritical
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir ↗Nucleicritical
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RIESGO
abrir ↗Nucleicritical
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
85RIESGO
abrir ↗Nucleihigh
Apache Kafka Client - Arbitrary File Read
Apache Kafka Client: Arbitrary file read and SSRF vulnerability
68RIESGO
abrir ↗Nucleihigh
Apache Druid - Server-Side Request Forgery
Apache Druid: Server-Side Request Forgery and Cross-Site Scripting
28RIESGO
abrir ↗Nucleicritical
Shopware < 6.5.8.13 - SQL Injection
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE:
33RIESGO
abrir ↗Nucleimedium
Zimbra - Cross-Site Scripting via ICS Files
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnera
58RIESGO
abrir ↗Nucleihigh
Electrolink FM/DAB/TV Transmitter - Credentials Disclosure
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and
36RIESGO
abrir ↗Nucleihigh
DAEnetIP4 METO v1.25 - Session Hijacking
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session
43RIESGO
abrir ↗Nucleimedium
mojoPortal <=2.9.0.1 - Directory Traversal
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. A
28RIESGO
abrir ↗Nucleimedium
Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
WordPress Skitter Slideshow plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerability
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.