Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleicritical
Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
43RIESGO
abrir
Nucleihigh
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File Read
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Unauthenticated Arbitrary File Read
48RIESGO
abrir
Nucleimedium
Custom Field Manager WordPress - Cross-Site Scripting
Custom Field Manager <= 1.0 - Reflected XSS Vulnerability
28RIESGO
abrir
Nucleimedium
Lazy Blocks <= 3.8.2 - Cross-Site Scripting
Custom Block Builder – Lazy Blocks < 3.8.3 - Reflected XSS
36RIESGO
abrir
Nucleicritical
DrayTek Vigor - Command Injection
CVE-2024-12987MEDIUMbajo ataque
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
100RIESGO
abrir
Nucleihigh
Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting
Dyn Business Panel <= 1.0.0 - Reflected XSS
36RIESGO
abrir
Nucleihigh
WP Triggers Lite - Cross-Site Scripting
WP Triggers Lite <= 2.5.3 - Reflected XSS
36RIESGO
abrir
Nucleimedium
WP Finance Plugin <= 1.3.6 - Cross-Site Scripting
WP Finance <= 1.3.6 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WordPress Email Newsletter - Reflected XSS
WP Email Newsletter <= 1.1 - Reflected XSS
28RIESGO
abrir
Nucleimedium
Widget4Call WordPress - Cross-Site Scripting
Widget4call <= 1.0.7 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WP MediaTagger <= 4.1.1 - Cross-Site Scripting
WP MediaTagger <= 4.1.1 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WP Projects Portfolio <= 3.0 - Cross-Site Scripting
WP Projects Portfolio with Client Testimonials <= 3.0 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WordPress Download Manager < 3.3.07 - Unauthenticated Data Exposure
Download Manager < 3.3.07 - Unauthenticated Data Exposure
28RIESGO
abrir
Nucleicritical
Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcardRecursive
CVE-2024-13159CRITICALbajo ataque
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir
Nucleicritical
Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcard
CVE-2024-13160CRITICALbajo ataque
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir
Nucleicritical
Ivanti EPM - Credential Coercion Vulnerability in GetHashForSingleFile
CVE-2024-13161CRITICALbajo ataque
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir
Nucleimedium
Privacy Policy Genius - Cross-Site Scripting
Policy Genius <= 2.0.4 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WordPress Google Map Professional - Cross-Site Scripting
Google Map Professional <= 1.0 - Reflected XSS
28RIESGO
abrir
Nucleimedium
Fantastic ElasticSearch Plugin <= 4.1.0 - Cross-Site Scripting
Fantastic Elasticsearch <= 4.1.0 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WordPress User Messages <= 1.2.4 - Reflected XSS
User Messages <= 1.2.4 - Reflected XSS
28RIESGO
abrir
Nucleimedium
SlideDeck 1 Lite Content Slider - Cross-Site Scripting
SlideDeck 1 Lite Content Slider <= 1.4.8 - Reflected XSS
28RIESGO
abrir
Nucleihigh
Pure-FTPd 1.0.23 < 1.0.50 - Arbitrary File Upload
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of
18RIESGO
abrir
Nucleicritical
Apache Cassandra Load UDF RCE
Remote code execution for scripted UDFs
30RIESGO
abrir
Nucleicritical
Redis Sandbox Escape - Remote Code Execution
CVE-2022-0543CRITICALbajo ataque
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
Nucleicritical
CouchDB Erlang Distribution - Remote Command Execution
CVE-2022-24706CRITICALbajo ataque
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir
Nucleihigh
muhttpd <=1.1.5 - Local Inclusion
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL wi
23RIESGO
abrir
Nucleihigh
TitanFTP move-file Function ≤ 1.94.1205 - Path Traversal
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RIESGO
abrir
Nucleicritical
RocketMQ <= 5.1.0 - Remote Code Execution
CVE-2023-33246CRITICALbajo ataque
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
Nucleicritical
Apache RocketMQ - Remote Command Execution
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir
Nucleicritical
Fortinet Forticlient Endpoint Management Server - SQL Injection
CVE-2023-48788CRITICALbajo ataqueransomware
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.