Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleicritical
Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
43RIESGO
abrir ↗Nucleihigh
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File Read
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Unauthenticated Arbitrary File Read
48RIESGO
abrir ↗Nucleimedium
Custom Field Manager WordPress - Cross-Site Scripting
Custom Field Manager <= 1.0 - Reflected XSS Vulnerability
28RIESGO
abrir ↗Nucleimedium
Lazy Blocks <= 3.8.2 - Cross-Site Scripting
Custom Block Builder – Lazy Blocks < 3.8.3 - Reflected XSS
36RIESGO
abrir ↗Nucleicritical
DrayTek Vigor - Command Injection
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
100RIESGO
abrir ↗Nucleihigh
Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting
Dyn Business Panel <= 1.0.0 - Reflected XSS
36RIESGO
abrir ↗Nucleihigh
WP Triggers Lite - Cross-Site Scripting
WP Triggers Lite <= 2.5.3 - Reflected XSS
36RIESGO
abrir ↗Nucleimedium
WP Finance Plugin <= 1.3.6 - Cross-Site Scripting
WP Finance <= 1.3.6 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
WordPress Email Newsletter - Reflected XSS
WP Email Newsletter <= 1.1 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
Widget4Call WordPress - Cross-Site Scripting
Widget4call <= 1.0.7 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
WP MediaTagger <= 4.1.1 - Cross-Site Scripting
WP MediaTagger <= 4.1.1 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
WP Projects Portfolio <= 3.0 - Cross-Site Scripting
WP Projects Portfolio with Client Testimonials <= 3.0 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
WordPress Download Manager < 3.3.07 - Unauthenticated Data Exposure
Download Manager < 3.3.07 - Unauthenticated Data Exposure
28RIESGO
abrir ↗Nucleicritical
Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcardRecursive
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir ↗Nucleicritical
Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcard
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir ↗Nucleicritical
Ivanti EPM - Credential Coercion Vulnerability in GetHashForSingleFile
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir ↗Nucleimedium
Privacy Policy Genius - Cross-Site Scripting
Policy Genius <= 2.0.4 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
WordPress Google Map Professional - Cross-Site Scripting
Google Map Professional <= 1.0 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
Fantastic ElasticSearch Plugin <= 4.1.0 - Cross-Site Scripting
Fantastic Elasticsearch <= 4.1.0 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
WordPress User Messages <= 1.2.4 - Reflected XSS
User Messages <= 1.2.4 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
SlideDeck 1 Lite Content Slider - Cross-Site Scripting
SlideDeck 1 Lite Content Slider <= 1.4.8 - Reflected XSS
28RIESGO
abrir ↗Nucleihigh
Pure-FTPd 1.0.23 < 1.0.50 - Arbitrary File Upload
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of
18RIESGO
abrir ↗Nucleicritical
Redis Sandbox Escape - Remote Code Execution
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir ↗Nucleicritical
CouchDB Erlang Distribution - Remote Command Execution
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir ↗Nucleihigh
muhttpd <=1.1.5 - Local Inclusion
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL wi
23RIESGO
abrir ↗Nucleihigh
TitanFTP move-file Function ≤ 1.94.1205 - Path Traversal
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RIESGO
abrir ↗Nucleicritical
RocketMQ <= 5.1.0 - Remote Code Execution
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir ↗Nucleicritical
Apache RocketMQ - Remote Command Execution
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir ↗Nucleicritical
Fortinet Forticlient Endpoint Management Server - SQL Injection
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.