Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4201 exploits
Nucleihigh
Microsoft Exchange - Authentication Bypass
Microsoft Exchange Server Information Disclosure Vulnerability
100RIESGO
abrir ↗Nucleimedium
npm ansi_up v4 - Cross-Site Scripting
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTM
18RIESGO
abrir ↗Nucleicritical
FortiLogger 4.4.2.2 - Arbitrary File Upload
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RIESGO
abrir ↗Nucleihigh
Cartadis Gespage 8.2.1 - Directory Traversal
Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.
23RIESGO
abrir ↗Nucleimedium
Drupal 7 CKEditor XSS
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1
18RIESGO
abrir ↗Nucleimedium
WordPress Customize Login Image <3.5.3 - Cross-Site Scripting
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an appl
18RIESGO
abrir ↗Nucleimedium
Accela Civic Platform <=21.1 - Cross-Site Scripting
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The
43RIESGO
abrir ↗Nucleicritical
Chamilo model.ajax.php - SQL Injection
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 p
23RIESGO
abrir ↗Nucleimedium
Accela Civic Platform <=21.1 - Cross-Site Scripting
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are
38RIESGO
abrir ↗Nucleicritical
Eclipse BIRT Viewer - Remote Code Execution
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessibl
50RIESGO
abrir ↗Nucleimedium
Eclipse Jetty - Information Disclosure
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RIESGO
abrir ↗Nucleicritical
Exchange Server - Remote Code Execution
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Nucleicritical
WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation Weakness
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RIESGO
abrir ↗Nucleicritical
WordPress ProfilePress <= 3.1.3 - Privilege Escalation
ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation
43RIESGO
abrir ↗Nucleicritical
WordPress ProfilePress 3.0-3.1.3 - Arbitrary File Upload
ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component
43RIESGO
abrir ↗Nucleimedium
GTranslate < 2.8.65 - Cross-Site Scripting
Reflected XSS in GTranslate Pro and GTranslate Enterprise < 2.8.65
28RIESGO
abrir ↗Nucleimedium
WordPress Securimage-WP-Fixed <=3.5.4 - Cross-Site Scripting
Securimage-WP-Fixed <= 3.5.4 Reflected Cross-Site Scripting
28RIESGO
abrir ↗Nucleimedium
WordPress Skaut Bazar <1.3.3 - Cross-Site Scripting
Skaut bazar <= 1.3.2 Reflected Cross-Site Scripting
28RIESGO
abrir ↗Nucleihigh
FAUST iServer 9.0.018.018.4 - Local File Inclusion
An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau
23RIESGO
abrir ↗Nucleicritical
Kramer VIAware - Privilege Escalation and Remote Code Execution
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn
60RIESGO
abrir ↗Nucleihigh
SolarWinds Serv-U 15.3 - Directory Traversal
Directory Transversal Vulnerability in Serv-U 15.3
61RIESGO
abrir ↗Nucleimedium
MaxSite CMS > V106 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attacke
18RIESGO
abrir ↗Nucleimedium
Bludit 3.13.1 - Cross Site Scripting
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RIESGO
abrir ↗Nucleicritical
Microsoft Open Management Infrastructure - Remote Code Execution
Open Management Infrastructure Remote Code Execution Vulnerability
100RIESGO
abrir ↗Nucleimedium
Cyberoam NetGenie Cross-Site Scripting
Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.
18RIESGO
abrir ↗Nucleimedium
ClinicCases 7.3.3 Cross-Site Scripting
Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to in
18RIESGO
abrir ↗Nucleimedium
ExponentCMS <= 2.6 - Host Header Injection
A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can cha
18RIESGO
abrir ↗Nucleihigh
XStream 1.4.18 - Remote Code Execution
XStream is vulnerable to an Arbitrary Code Execution attack
41RIESGO
abrir ↗Nucleihigh
XStream 1.4.18 - Remote Code Execution
XStream is vulnerable to a Remote Command Execution attack
100RIESGO
abrir ↗Nucleihigh
XStream 1.4.18 - Arbitrary Code Execution
XStream is vulnerable to an Arbitrary Code Execution attack
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.