Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4201 exploits
Nucleimedium
Jenkins Gitlab Hook <=1.4.2 - Cross-Site Scripting
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref
60RIESGO
abrir ↗Nucleicritical
shadoweb wdja v1.5.1 - Cross-Site Scripting
Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain es
18RIESGO
abrir ↗Nucleimedium
DomainMOD 4.13.0 - Cross-Site Scripting
A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attacker
18RIESGO
abrir ↗Nucleimedium
Jenkins <=2.218 - Information Disclosure
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI d
18RIESGO
abrir ↗Nucleicritical
Inspur ClusterEngine 4.0 - Remote Code Execution
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a maliciou
30RIESGO
abrir ↗Nucleimedium
Jenkin Audit Trail <=3.2 - Cross-Site Scripting
Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation,
40RIESGO
abrir ↗Nucleimedium
HomeAutomation 3.3.2 - Open Redirect
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified befor
18RIESGO
abrir ↗Nucleihigh
PHPGurukul Hospital Management System 4.0 - SQL Injection
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unaut
18RIESGO
abrir ↗Nucleicritical
74cms - ajax_street.php 'x' SQL Injection
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
18RIESGO
abrir ↗Nucleicritical
74cms - ajax_common.php SQL Injection
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
18RIESGO
abrir ↗Nucleicritical
74cms - ajax_officebuilding.php SQL Injection
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
18RIESGO
abrir ↗Nucleicritical
74cms - ajax_street.php 'key' SQL Injection
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
18RIESGO
abrir ↗Nucleimedium
b2evolution CMS <6.11.6 - Open Redirect
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redi
23RIESGO
abrir ↗Nucleimedium
OPNsense <=20.1.5 - Open Redirect
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not fil
18RIESGO
abrir ↗Nucleimedium
Aryanic HighMail (High CMS) - Cross-Site Scripting
Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers
18RIESGO
abrir ↗Nucleihigh
Kyocera Printer d-COPIA253MF - Directory Traversal
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnera
30RIESGO
abrir ↗Nucleimedium
Monstra CMS 3.0.4 - Cross-Site Scripting
Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.
18RIESGO
abrir ↗Nucleimedium
XXL-JOB v2.2.0 — Stored Cross Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web scr
18RIESGO
abrir ↗Nucleihigh
Joomla! Component GMapFP 3.5 - Arbitrary File Upload
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating
50RIESGO
abrir ↗Nucleicritical
Import XML & RSS Feeds WordPress Plugin <= 2.0.1 Server-Side Request Forgery
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the
23RIESGO
abrir ↗Nucleicritical
WordPress wpDiscuz <=7.0.4 - Remote Code Execution
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir ↗Nucleimedium
Mara CMS 7.5 - Cross-Site Scripting
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
43RIESGO
abrir ↗Nucleihigh
INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion
INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgi
18RIESGO
abrir ↗Nucleihigh
WordPress Plugin File Manager (wp-file-manager) Backup Disclosure
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htacce
23RIESGO
abrir ↗Nucleicritical
Mongo-Express - Remote Code Execution
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this m
40RIESGO
abrir ↗Nucleimedium
EpiServer Find <13.2.7 - Open Redirect
An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted website
18RIESGO
abrir ↗Nucleihigh
NexusDB <4.50.23 - Local File Inclusion
NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
23RIESGO
abrir ↗Nucleihigh
D-Link DSL 2888a - Authentication Bypass/Remote Command Execution
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attac
18RIESGO
abrir ↗Nucleicritical
WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection
48RIESGO
abrir ↗Nucleimedium
OX Appsuite - Cross-Site Scripting
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
18RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.