Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4201 exploits
Nucleihigh
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RIESGO
abrir ↗Nucleicritical
Cisco IOS XE WLC - Arbitrary File Upload
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de
68RIESGO
abrir ↗Nucleicritical
Cisco ISE - Remote Code Execution
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RIESGO
abrir ↗Nucleimedium
Cisco Secure Firewall ASA & FTD - Authentication Bypass
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar
100RIESGO
abrir ↗Nucleihigh
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
36RIESGO
abrir ↗Nucleimedium
JoomlaUX JUX Real Estate 3.4.0 - Reflected XSS
JoomlaUX JUX Real Estate realties cross site scripting
28RIESGO
abrir ↗Nucleimedium
Mage AI - Insecure Default Authentication Setup
Mage AI insecure default initialization of resource
28RIESGO
abrir ↗Nucleihigh
WordPress WPCOM Member <= 1.7.6 - SQL Injection
WPCOM Member <= 1.7.6 - Unauthenticated Time-Based SQL Injection
36RIESGO
abrir ↗Nucleicritical
Landray EIS SQL注入漏洞
Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.
28RIESGO
abrir ↗Nucleihigh
Sante PACS Server.exe - Path Traversal Information Disclosure
Santesoft Sante PACS Server Path Traversal Information Disclosure
48RIESGO
abrir ↗Nucleicritical
Course Booking System <= 6.0.6 - SQL Injection
WordPress Course Booking System plugin <= 6.0.6 - SQL Injection vulnerability
63RIESGO
abrir ↗Nucleicritical
Kubio AI Page Builder <= 2.5.1 - Local File Inclusion
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir ↗Nucleicritical
Elestio Memos <= v0.24.0 - Server-Side Request Forgery
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplie
43RIESGO
abrir ↗Nucleicritical
Mongoose - NoSQL Injection
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NO
63RIESGO
abrir ↗Nucleicritical
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006)
Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
100RIESGO
abrir ↗Nucleimedium
Kentico Xperience CMS - Unauthenticated Stored XSS
Kentico Xperience stored cross-site scripting in multiple-file upload functionality
60RIESGO
abrir ↗Nucleimedium
GeoServer - Missing Authorization on REST API Index
GeoServer Missing Authorization on REST API Index
28RIESGO
abrir ↗Nucleimedium
NocoDB < 0.258.0 - Reflected XSS in Password Reset
NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page
28RIESGO
abrir ↗Nucleicritical
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir ↗Nucleicritical
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RIESGO
abrir ↗Nucleicritical
SysAid On-Prem <= 23.3.40 - XML External Entity
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
85RIESGO
abrir ↗Nucleihigh
Apache Kafka Client - Arbitrary File Read
Apache Kafka Client: Arbitrary file read and SSRF vulnerability
68RIESGO
abrir ↗Nucleihigh
Apache Druid - Server-Side Request Forgery
Apache Druid: Server-Side Request Forgery and Cross-Site Scripting
28RIESGO
abrir ↗Nucleicritical
Shopware < 6.5.8.13 - SQL Injection
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE:
33RIESGO
abrir ↗Nucleimedium
Zimbra - Cross-Site Scripting via ICS Files
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnera
58RIESGO
abrir ↗Nucleihigh
Electrolink FM/DAB/TV Transmitter - Credentials Disclosure
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and
36RIESGO
abrir ↗Nucleihigh
DAEnetIP4 METO v1.25 - Session Hijacking
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session
43RIESGO
abrir ↗Nucleimedium
mojoPortal <=2.9.0.1 - Directory Traversal
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. A
28RIESGO
abrir ↗Nucleimedium
Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
WordPress Skitter Slideshow plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerability
28RIESGO
abrir ↗Nucleicritical
Order Delivery Date Pro for WooCommerce < 12.3.1 - Arbitrary Option Update
Order Delivery Date Pro for WooCommerce < 12.3.1 - Unauthenticated Arbitrary Option Update
63RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.