Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleicritical
Versa Concerto API Path Based - Authentication Bypass
Versa Concerto Authentication Bypass File Write Remote Code Execution
75RIESGO
abrir
Nucleicritical
Commvault - SSRF via /commandcenter/deployWebpackage.do
CVE-2025-34028CRITICALbajo ataque
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir
Nucleicritical
sar2html <=3.2.2 Plot Parameter - Remote Code Execution
sar2html OS Command Injection
75RIESGO
abrir
Nucleihigh
Moodle Jmol Filter 6.1 - Local File Inclusion
Moodle LMS Jmol Plugin Path Traversal
36RIESGO
abrir
Nucleimedium
Moodle LMS Jmol Plugin <= 6.1 - Cross-Site Scripting
Moodle LMS Jmol Plugin Cross-site Scripting (XSS)
28RIESGO
abrir
Nucleicritical
EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 Root Remote Code Execution
EnGenius EnShare IoT Gigabit Cloud Service Command Injection
68RIESGO
abrir
Nucleihigh
Fanwei e-cology - SQL Injection
Weaver E-cology SQL Injection
36RIESGO
abrir
Nucleicritical
Zhiyuan OA Platform - Arbitrary File Upload
Seeyon Zhiyuan OA System Path Traversal File Upload
68RIESGO
abrir
Nucleihigh
WeiPHP 5.0 - Path Traversal
WeiPHP Path Traversal Arbitrary File Read
36RIESGO
abrir
Nucleicritical
Maltrail <=0.54 Username Parameter - Remote Command Execution
stamparm/maltrail <=0.54 Remote Command Execution
63RIESGO
abrir
Nucleicritical
WordPress Pie Register <= 3.7.1.4 - Authentication Bypass
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir
Nucleicritical
WordPress Simple File List <=4.2.2 - Remote Code Execution
35RIESGO
abrir
Nucleimedium
ETQ Reliance - Reflected XSS via SQLConverterServlet
ETQ Reliance CG < SE.2025.1 Reflected XSS in `SQLConverterServlet`
28RIESGO
abrir
Nucleicritical
ETQ Reliance - Authentication Bypass via Trailing Space
ETQ Reliance CG Authentication Bypass via Trailing Space RCE
48RIESGO
abrir
Nucleimedium
Grafana - Exposes DingDing API Keys
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p
28RIESGO
abrir
Nucleicritical
Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via `time` Parameter
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir
Nucleicritical
Langflow AI <= 1.6.9 - CORS Misconfiguration
CVE-2025-34291CRITICALbajo ataque
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
100RIESGO
abrir
Nucleicritical
Monsta FTP <= 2.11.2 - Unauthenticated Remote Code Execution
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir
Nucleicritical
SawtoothSoftware Lighthouse Studio < 9.16.14 - Pre-Auth Remote Code Execution
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RIESGO
abrir
Nucleihigh
Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials
Sitecore XM and XP Hardcoded Credentials
48RIESGO
abrir
Nucleimedium
Ocean Extra <= 2.4.6 - Unauthenticated Shortcode Execution
Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution
28RIESGO
abrir
Nucleihigh
Contact Form 7 Drag and Drop Multiple File Upload - Arbitrary File Upload
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RIESGO
abrir
Nucleicritical
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RIESGO
abrir
Nucleicritical
Dell UnityVSA < 5.5 - Remote Command Injection
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('
68RIESGO
abrir
Nucleihigh
Eveo URVE Web Manager - Server-Side Request Forgery
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side
36RIESGO
abrir
Nucleicritical
HPE OneView - Remote Code Execution
CVE-2025-37164CRITICALbajo ataque
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir
Nucleihigh
Personal Weather Station Dashboard 12 - Directory Traversal
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ direct
28RIESGO
abrir
Nucleihigh
WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download
WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
36RIESGO
abrir
Nucleicritical
Eventin <= 4.0.26 - Privilege Escalation
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RIESGO
abrir
Nucleihigh
TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Upload
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RIESGO
abrir
anteriorpágina 133 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.