Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
4320 exploits
Nucleicritical
Control Web Panel (CWP) - File Inclusion
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to c
65RIESGO
abrir ↗Nucleihigh
Slims9 Bulian 9.4.2 - SQL Injection
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
18RIESGO
abrir ↗Nucleimedium
osTicket 1.15.x - SQL Injection
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticate
18RIESGO
abrir ↗Nucleicritical
Pascom CPS Server-Side Request Forgery
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend To
23RIESGO
abrir ↗Nucleihigh
Pascom CPS - Local File Inclusion
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Pho
23RIESGO
abrir ↗Nucleimedium
Sourcecodester Car Rental Management System 1.0 - Stored Cross-Site Scripting
Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter
18RIESGO
abrir ↗Nucleimedium
Vehicle Service Management System - Stored Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Sec
18RIESGO
abrir ↗Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List
18RIESGO
abrir ↗Nucleimedium
ehicle Service Management System 1.0 - Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List
18RIESGO
abrir ↗Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List S
18RIESGO
abrir ↗Nucleimedium
Vehicle Service Management System 1.0 - Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the
18RIESGO
abrir ↗Nucleihigh
webp_server_go 0.4.0 - Path Traversal
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi
18RIESGO
abrir ↗Nucleihigh
Ligeo Archives Ligeo Basics - Server Side Request Forgery
Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacke
18RIESGO
abrir ↗Nucleihigh
AntD Admin - Sensitive Information Disclosure
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the
18RIESGO
abrir ↗Nucleimedium
D-Link DIR850 ET850-1.08TRb03 - Open Redirect
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RIESGO
abrir ↗Nucleihigh
D-Link DAP-1620 - Local File Inclusion
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RIESGO
abrir ↗Nucleimedium
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RIESGO
abrir ↗Nucleihigh
Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RIESGO
abrir ↗Nucleihigh
Telesquare TLR-2855KS6 - Arbitrary File Creation
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
43RIESGO
abrir ↗Nucleicritical
Telesquare TLR-2855KS6 - Arbitrary File Deletion
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil
60RIESGO
abrir ↗Nucleicritical
SDT-CW3B1 1.1.0 - OS Command Injection
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RIESGO
abrir ↗Nucleicritical
Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de
50RIESGO
abrir ↗Nucleicritical
GenieACS => 1.2.8 - OS Command Injection
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping
23RIESGO
abrir ↗Nucleihigh
GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scripting
GeoVision Geowebserver 5.3.3 - Local FIle Inclusion
36RIESGO
abrir ↗Nucleimedium
Keystone 6 Login Page - Open Redirect and Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in keystonejs/keystone
36RIESGO
abrir ↗Nucleimedium
WordPress Visual Form Builder <3.0.8 - Information Disclosure
Visual Form Builder < 3.0.6 - Unauthenticated Information Disclosure
18RIESGO
abrir ↗Nucleimedium
WordPress Cookie Information/Free GDPR Consent Solution <2.0.8 - Cross-Site Scripting
Cookie Information < 2.0.8 - Reflected Cross-Site Scripting
18RIESGO
abrir ↗Nucleimedium
WordPress All-in-one Floating Contact Form <2.0.4 - Cross-Site Scripting
All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)
18RIESGO
abrir ↗Nucleimedium
WooCommerce Stored Exporter WordPress Plugin < 2.7.1 - Cross-Site Scripting
WooCommerce – Store Exporter < 2.7.1 - Reflected Cross-Site Scripting (XSS)
18RIESGO
abrir ↗Nucleimedium
WordPress Accessibility Helper <0.6.0.7 - Cross-Site Scripting
WP Accessibility Helper (WAH) < 0.6.0.7 - Reflected Cross-Site Scripting (XSS)
18RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.