Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
4361 exploits
Nucleimedium
kkFileView 4.1.0 - Cross-Site Scripting
kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control
28RIESGO
abrir ↗Nucleicritical
Masa CMS - Authentication Bypass
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authenticatio
18RIESGO
abrir ↗Nucleicritical
Mura CMS <10.0.580 - Authentication Bypass
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a
43RIESGO
abrir ↗Nucleihigh
Smart Office Web 20.28 - Information Disclosure
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RIESGO
abrir ↗Nucleihigh
Apache OFBiz < 18.12.07 - Local File Inclusion
Apache OFBiz: Arbitrary file reading vulnerability
41RIESGO
abrir ↗Nucleicritical
LearnPress Plugin < 4.2.0 - Local File Inclusion
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion
63RIESGO
abrir ↗Nucleicritical
Thinkphp Lang - Local File Inclusion
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is en
48RIESGO
abrir ↗Nucleicritical
ManageEngine - Remote Command Execution
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir ↗Nucleicritical
IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution
IBM Aspera Faspex code execution
100RIESGO
abrir ↗Nucleimedium
OpenCATS 0.9.7 - Cross-Site Scripting
Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openca
28RIESGO
abrir ↗Nucleihigh
Wavlink WL-WN533A8 M33A8.V5030.190716 - Information Disclosure
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthen
36RIESGO
abrir ↗Nucleihigh
Wavlink - Improper Access Control
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthen
18RIESGO
abrir ↗Nucleihigh
Wavlink WL-WN530HG4 M30HG4.V5030.201217 - Information Disclosure
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configur
36RIESGO
abrir ↗Nucleimedium
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site Scripting
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RIESGO
abrir ↗Nucleicritical
Sunflower Simple and Personal 1.0.1.43315 - Remote Code Execution
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A
75RIESGO
abrir ↗Nucleimedium
WordPress BackupBuddy <8.8.3 - Cross Site Scripting
BackupBuddy < 8.8.3 - Multiple Reflected Cross-Site Scripting
28RIESGO
abrir ↗Nucleihigh
WCFM Membership <= 2.10.0 - Broken Access Control
WCFM Membership <= 2.10.0 - Missing Authorization
36RIESGO
abrir ↗Nucleimedium
Sassy Social Share <= 3.3.3 - Cross-Site Scripting
Sassy Social Share <= 3.3.3 - Reflected Cross-Site Scripting
33RIESGO
abrir ↗Nucleicritical
WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injection
10WebMapBuilder < 1.0.73 - Unauthenticated SQLi
63RIESGO
abrir ↗Nucleimedium
Simple URLs < 115 - Cross Site Scripting
Simple URLs < 115 - Multiple Reflected XSS
18RIESGO
abrir ↗Nucleihigh
SonicWall SMA1000 LFI
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated atta
58RIESGO
abrir ↗Nucleihigh
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RIESGO
abrir ↗Nucleimedium
WordPress Tutor LMS <2.0.10 - Cross Site Scripting
Tutor LMS < 2.0.10 - Reflected Cross-Site Scripting
28RIESGO
abrir ↗Nucleihigh
WordPress WP TripAdvisor Review Slider <10.8 - Authenticated SQL Injection
WP TripAdvisor Review Slider < 10.8 - Subscriber+ SQLi
36RIESGO
abrir ↗Nucleicritical
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
Code Injection in pyload/pyload
85RIESGO
abrir ↗Nucleimedium
ShortPixel Adaptive Images < 3.6.3 - Cross Site Scripting
ShortPixel Adaptive Images < 3.6.3 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
WP Helper Lite < 4.3 - Cross-Site Scripting
The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resultin
40RIESGO
abrir ↗Nucleimedium
Membership Database <= 1.0 - Cross-Site Scripting
Membership Database <= 1.0 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
Online Security Guards Hiring System - Cross-Site Scripting
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RIESGO
abrir ↗Nucleimedium
WordPress Pie Register <3.8.2.3 - Open Redirect
Pie Register < 3.8.2.3 - Open Redirect
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.