Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8150Nuclei 4193Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4193 exploits
Nucleicritical
Tenda Router AC11 - Remote Command Injection
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerabili
95RIESGO
abrir ↗Nucleicritical
Apache Struts2 S2-062 - Remote Code Execution
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RIESGO
abrir ↗Nucleicritical
Layer5 Meshery 0.5.2 - SQL Injection
A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL comman
40RIESGO
abrir ↗Nucleimedium
SysAid 20.4.74 - Cross-Site Scripting
SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.
18RIESGO
abrir ↗Nucleicritical
ASUS GT-AC2900 - Authentication Bypass
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630
95RIESGO
abrir ↗Nucleicritical
Maian Cart <=3.8 - Remote Code Execution
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RIESGO
abrir ↗Nucleihigh
Node RED Dashboard <2.26.2 - Local File Inclusion
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
23RIESGO
abrir ↗Nucleicritical
Websvn <2.6.1 - Remote Code Execution
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search paramet
60RIESGO
abrir ↗Nucleicritical
E-Learning System 1.0 - SQL Injection
E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to exec
23RIESGO
abrir ↗Nucleimedium
Moodle 3.8-3.10.3 - Reflected XSS & Open Redirect
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect
18RIESGO
abrir ↗Nucleicritical
elFinder 2.1.58 - Remote Code Execution
Multiple vulnerabilities leading to RCE
75RIESGO
abrir ↗Nucleihigh
WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injection
Arbitrary SQL (SQL injection) possible via the Store API component.
61RIESGO
abrir ↗Nucleihigh
Nodejs Squirrelly - Remote Code Execution
Remote code execution in squirrelly
68RIESGO
abrir ↗Nucleihigh
Express-handlebars - Local File Inclusion
File disclosure in Express Handlebars
23RIESGO
abrir ↗Nucleicritical
Erxes <0.23.0 - Cross-Site Scripting
Erxes vulnerable to Cross-site Scripting
28RIESGO
abrir ↗Nucleicritical
Zoho ManageEngine OpManager < 12.5.329 - Remote Code Execution
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the
30RIESGO
abrir ↗Nucleimedium
emlog 5.3.1 Path Disclosure
emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webr
23RIESGO
abrir ↗Nucleihigh
Zyxel NBG2105 V1.00(AAGU.2)C0 - Authentication Bypass
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
23RIESGO
abrir ↗Nucleicritical
Dahua IPC/VTH/VTO - Authentication Bypass
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir ↗Nucleicritical
Dahua IPC/VTH/VTO - Authentication Bypass
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir ↗Nucleicritical
CommScope Ruckus IoT Controller - Information Disclosure
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
30RIESGO
abrir ↗Nucleicritical
RaspAP <=2.6.5 - Remote Command Injection
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the
23RIESGO
abrir ↗Nucleihigh
Geutebruck - Remote Command Injection
UDP Technology/Geutebrück camera devices: command injection leading to RCE
58RIESGO
abrir ↗Nucleihigh
Boa 0.94.13 - Information Disclosure
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, previe
43RIESGO
abrir ↗Nucleicritical
Ruby Dragonfly <1.4.0 - Remote Code Execution
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write
60RIESGO
abrir ↗Nucleicritical
SAP NetWeaver Development Infrastructure - Server Side Request Forgery
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RIESGO
abrir ↗Nucleimedium
Rstudio Shiny Server <1.5.16 - Local File Inclusion
Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involvin
23RIESGO
abrir ↗Nucleihigh
Microsoft Exchange - Authentication Bypass
Microsoft Exchange Server Information Disclosure Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.