Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
4361 exploits
Nucleihigh
D-Link DIR-823X set_prohibiting - Command Injection
CVE-2025-29635HIGHbajo ataque
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrar
88RIESGO
abrir
Nucleihigh
XWiki REST API - Private Pages Disclosure
XWiki allows unregistered users to access private pages information through REST endpoint
36RIESGO
abrir
Nucleicritical
Next.js Middleware Bypass
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
Nucleimedium
Vite - Arbitrary File Read
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
Nucleicritical
GeoServer WFS - XXE Processing Vulnerability
GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling
55RIESGO
abrir
Nucleicritical
Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE
CVE-2025-30406CRITICALbajo ataque
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir
Nucleihigh
WordPress WP01 - Path Traversal
WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability
56RIESGO
abrir
Nucleihigh
SureTriggers – All-in-One Automation Platform ≤ 1.0.78 - Authentication Bypass
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RIESGO
abrir
Nucleimedium
Vite Development Server - Path Traversal
CVE-2025-31125MEDIUMbajo ataque
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir
Nucleihigh
Yeswiki < 4.5.2 - Unauthenticated Path Traversal
Path Traversal allowing arbitrary read of files in Yeswiki
56RIESGO
abrir
Nucleicritical
CrushFTP - Authentication Bypass
CVE-2025-31161CRITICALbajo ataqueransomware
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
Nucleicritical
SAP NetWeaver Visual Composer Metadata Uploader - Deserialization
CVE-2025-31324CRITICALbajo ataqueransomware
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
Nucleimedium
Vite server.fs.deny Bypass - Local File Inclusion
Vite allows server.fs.deny to be bypassed with .svg or relative paths
40RIESGO
abrir
Nucleihigh
MinIO - Incomplete Signature Validation for Unsigned-Trailer Uploads
MinIO performs incomplete signature validation for unsigned-trailer uploads
36RIESGO
abrir
Nucleimedium
1 Click WordPress Migration <= 2.2 - Unauthenticated Information Disclsoure
WordPress 1 Click WordPress Migration plugin <= 2.5.7 - Sensitive Data Exposure vulnerability
28RIESGO
abrir
Nucleihigh
Rocket TRUfusion Enterprise - Server Side Request Forgery
Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is
36RIESGO
abrir
Nucleimedium
Vite - Path Traversal
Vite has an `server.fs.deny` bypass with an invalid `request-target`
28RIESGO
abrir
Nucleicritical
XWiki Platform - SQL Injection
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir
Nucleimedium
XWiki Platform - Cross-Site Scripting
XWiki Platform contains Reflected XSS vulnerability in two templates
28RIESGO
abrir
Nucleicritical
CraftCMS - Remote Code Execution
CVE-2025-32432CRITICALbajo ataque
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
Nucleicritical
Langflow AI - Unauthenticated Remote Code Execution
CVE-2025-3248CRITICALbajo ataqueransomware
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
Nucleihigh
EventON Lite <= 2.4 - Authenticated Local File Inclusion
WordPress EventON plugin <= 2.4 - Local File Inclusion vulnerability
36RIESGO
abrir
Nucleicritical
Web-Check < 2.0.1 Screenshot API - OS Command Injection
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir
Nucleihigh
Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
48RIESGO
abrir
Nucleicritical
NetMRI Unauthenticated SQL Injection via skipjackUsername
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
55RIESGO
abrir
Nucleimedium
NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentials
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
40RIESGO
abrir
Nucleicritical
DataEase 2.10.4-2.10.7 - Remote Code Execution
Dataease H2 JDBC Connection Remote Code Execution
36RIESGO
abrir
Nucleicritical
XWiki REST API Query - SQL Injection
org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API
65RIESGO
abrir
Nucleimedium
XWiki WYSIWYG API - Open Redirect
org.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerability
28RIESGO
abrir
Nucleihigh
Karel IP Phone IP1211 Web Management Panel - Local File Inclusion
Karel IP Phone IP1211 Path Traversal
36RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.