Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
4320 exploits
Nucleimedium
Admidio - Cross-Site Scripting
Cross-site Scripting (XSS) when redirect an url
36RIESGO
abrir ↗Nucleihigh
Gradio < 2.5.0 - Arbitrary File Read
Files on the host computer can be accessed from the Gradio interface
36RIESGO
abrir ↗Nucleicritical
Zoho ManageEngine ServiceDesk Plus - Remote Code Execution
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RIESGO
abrir ↗Nucleihigh
Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remo
23RIESGO
abrir ↗Nucleihigh
Alibaba Sentinel - Server-side request forgery (SSRF)
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
18RIESGO
abrir ↗Nucleicritical
Reprise License Manager 14.2 - Authentication Bypass
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a
30RIESGO
abrir ↗Nucleicritical
Apache Log4j2 Remote Code Injection
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Nucleihigh
WAVLINK AC1200 - Information Disclosure
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can al
18RIESGO
abrir ↗Nucleicritical
3DPrint Lite < 1.9.1.5 - Arbitrary File Upload
3DPrint Lite < 1.9.1.5 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗Nucleicritical
Rosario Student Information System Unauthenticated SQL Injection
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allow
55RIESGO
abrir ↗Nucleihigh
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
36RIESGO
abrir ↗Nucleicritical
ZoomSounds Plugin - Unauthenticated Arbitrary File Upload
ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
43RIESGO
abrir ↗Nucleicritical
Zoho ManageEngine Desktop Central - Remote Code Execution
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server
95RIESGO
abrir ↗Nucleimedium
Open Redirect in Host Authorization Middleware
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host"
18RIESGO
abrir ↗Nucleicritical
Ivanti EPM Cloud Services Appliance Code Injection
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RIESGO
abrir ↗Nucleicritical
Employee Records System 1.0 - Unauthenticated File Upload RCE
Employee Records System v1.0 Arbitrary File Upload RCE
63RIESGO
abrir ↗Nucleihigh
Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download
Longjing Technology BEMS API <= 1.21 Remote Arbitrary File Download
36RIESGO
abrir ↗Nucleimedium
Thinfinity VirtualUI User Enumeration
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RIESGO
abrir ↗Nucleihigh
Oliver 5 Library Server <8.00.008.053 - Local File Inclusion
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet functio
18RIESGO
abrir ↗Nucleihigh
HD-Network Realtime Monitoring System 2.0 - Local File Inclusion
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RIESGO
abrir ↗Nucleicritical
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir ↗Nucleicritical
Thinfinity Iframe Injection
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RIESGO
abrir ↗Nucleicritical
Apache APISIX Dashboard <2.10.1 - API Unauthorized Access
security vulnerability on unauthorized access.
40RIESGO
abrir ↗Nucleimedium
Gitea < 1.4.3 - Open Redirect
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
18RIESGO
abrir ↗Nucleimedium
AppCMS - Cross-Site Scripting
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
18RIESGO
abrir ↗Nucleicritical
D-Link - Remote Command Execution
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L
95RIESGO
abrir ↗Nucleicritical
Emerson Dixell XWEB-500 - Arbitrary File Write
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /
23RIESGO
abrir ↗Nucleimedium
Reprise License Manager 14.2 - Cross-Site Scripting
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_proce
18RIESGO
abrir ↗Nucleicritical
Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Upload
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.