Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8150Nuclei 4193Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4193 exploits
Nucleicritical
EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 Root Remote Code Execution
EnGenius EnShare IoT Gigabit Cloud Service Command Injection
68RIESGO
abrir ↗Nucleicritical
Zhiyuan OA Platform - Arbitrary File Upload
Seeyon Zhiyuan OA System Path Traversal File Upload
68RIESGO
abrir ↗Nucleicritical
Maltrail <=0.54 Username Parameter - Remote Command Execution
stamparm/maltrail <=0.54 Remote Command Execution
63RIESGO
abrir ↗Nucleicritical
WordPress Pie Register <= 3.7.1.4 - Authentication Bypass
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir ↗Nucleimedium
ETQ Reliance - Reflected XSS via SQLConverterServlet
ETQ Reliance CG < SE.2025.1 Reflected XSS in `SQLConverterServlet`
28RIESGO
abrir ↗Nucleicritical
ETQ Reliance - Authentication Bypass via Trailing Space
ETQ Reliance CG Authentication Bypass via Trailing Space RCE
48RIESGO
abrir ↗Nucleimedium
Grafana - Exposes DingDing API Keys
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p
28RIESGO
abrir ↗Nucleicritical
Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via `time` Parameter
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir ↗Nucleicritical
Langflow AI <= 1.6.9 - CORS Misconfiguration
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
100RIESGO
abrir ↗Nucleicritical
Monsta FTP <= 2.11.2 - Unauthenticated Remote Code Execution
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗Nucleihigh
YesWiki Reflected XSS via File Upload
YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
36RIESGO
abrir ↗Nucleimedium
Broadstreet WordPress plugin - Reflected XSS
Broadstreet < 1.51.8 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
YesWiki <= 4.5.1 - Cross-Site Scripting
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
28RIESGO
abrir ↗Nucleimedium
YesWiki < 4.5.4 - Cross-Site Scripting
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
28RIESGO
abrir ↗Nucleihigh
XWiki REST API - Attachments Disclosure
XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API
28RIESGO
abrir ↗Nucleimedium
Vite Dev Server - Information Exposure
Vite's server.fs.deny bypassed with /. for files under project root
28RIESGO
abrir ↗Nucleihigh
Java-springboot-codebase 1.1 - Arbitrary File Read
Unauthenticated Arbitrary File Read via Absolute Path
56RIESGO
abrir ↗Nucleicritical
Mitel 6000 - OS Command Injection
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th
40RIESGO
abrir ↗Nucleimedium
Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting
An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the sour
28RIESGO
abrir ↗Nucleihigh
Personal Weather Station Dashboard 12 - Directory Traversal
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ direct
28RIESGO
abrir ↗Nucleihigh
WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download
WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
36RIESGO
abrir ↗Nucleicritical
Eventin <= 4.0.26 - Privilege Escalation
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RIESGO
abrir ↗Nucleihigh
TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Upload
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RIESGO
abrir ↗Nucleicritical
PSW Front-end Login & Registration 1.13 - Weak Password Recovery
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RIESGO
abrir ↗Nucleimedium
Label Studio < 1.18.0 - Reflected XSS
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
36RIESGO
abrir ↗Nucleicritical
Wing FTP Server <= 7.4.3 - Remote Code Execution
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗Nucleimedium
Wing FTP Server <= 7.4.3 - Path Disclosure via Overlong UID Cookie
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
70RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.