Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleicritical
Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserialization
CVE-2025-5086CRITICALbajo ataque
Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
95RIESGO
abrir
Nucleihigh
Letta Letta 0.7.12 - Remote Code Execution
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem
56RIESGO
abrir
Nucleimedium
Microweber CMS2.0 - Cross-Site Scripting
Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS
28RIESGO
abrir
Nucleimedium
Microweber CMS 2.0 - Reflected XSS in Admin Page Creation
Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allow
28RIESGO
abrir
Nucleimedium
PrestaShop - Information Disclosure
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers
23RIESGO
abrir
Nucleimedium
XWiki – Stored Cross-Site Scripting (XSS)
XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administra
28RIESGO
abrir
Nucleicritical
XWiki <= 17.3.0 - Server-Side Template Injection (SSTI)
XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, spe
36RIESGO
abrir
Nucleicritical
MikoPBX - Unrestricted File Upload
PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbit
43RIESGO
abrir
Nucleihigh
XWiki - HQL Injection
XWiki Platform vulnerable to HQL injection via wiki and space search REST API
43RIESGO
abrir
Nucleihigh
DNN (DotNetNuke) - Unicode Path Normalization NTLM Hash Disclosure
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
68RIESGO
abrir
Nucleicritical
UniFi Access - Broken Access Control
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access applicat
55RIESGO
abrir
Nucleicritical
SmarterMail - Unrestricted File Upload
CVE-2025-52691CRITICALbajo ataqueransomware
Upload Arbitrary Files
100RIESGO
abrir
Nucleihigh
LiquidFiles < 4.2 - User Enumeration via Password Reset
LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The appli
56RIESGO
abrir
Nucleimedium
Avigilon ACM - Host Header Injection
A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplyin
43RIESGO
abrir
Nucleihigh
Dify v1.6.0 - Server-Side Request Forgery
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_
28RIESGO
abrir
Nucleicritical
Datart v1.0.0-rc.3 - Remote Code Execution
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
63RIESGO
abrir
Nucleicritical
HyperComments <= 1.2.2 - Arbitrary Options Update
HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update
36RIESGO
abrir
Nucleicritical
Citrix NetScaler Memory Disclosure - CitrixBleed 2
CVE-2025-5777CRITICALbajo ataqueransomware
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
Nucleimedium
Commvault Unauthenticated Password Disclosure (WT-2025-0047)
Unauthorized API Access Risk
28RIESGO
abrir
Nucleimedium
Commvault Initial Administrator Login Process Vulnerability
Vulnerability in Initial Administrator Login Process
28RIESGO
abrir
Nucleihigh
ESPHome - Authentication Bypass
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
36RIESGO
abrir
Nucleicritical
FreePBX - Remote Code Execution
CVE-2025-57819CRITICALbajo ataque
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
Nucleimedium
Next.js Middleware - Server-Side Request Forgery
Next.js Improper Middleware Redirect Handling Leads to SSRF
28RIESGO
abrir
Nucleimedium
JumpServer - Open Redirect via Referer Header
JumpServer has an Open Redirect Vulnerability
28RIESGO
abrir
Nucleihigh
Astro Cloudflare Adapter - Server Side Request Forgery
Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint
36RIESGO
abrir
Nucleimedium
WordPress 3D FlipBook Plugin <= 1.16.17 - Sensitive Information Exposure
WordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure Vulnerability
28RIESGO
abrir
Nucleihigh
GeoServer - XML External Entity Injection
CVE-2025-58360HIGHbajo ataque
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
Nucleicritical
Flowise <= 3.0.5 - Account Takeover
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir
Nucleicritical
FOGProject <= 1.5.10.1673 - Authentication Bypass
FOG's authentication bypass leads to full SQL DB dump
68RIESGO
abrir
Nucleilow
Vite Dev Server - Path Traversal
Vite middleware may serve files starting with the same name with the public directory
23RIESGO
abrir
anteriorpágina 136 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.