Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleimedium
Joomla! Webservice - Password Disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗Nucleimedium
Ozette Plugins - Cross-Site Request Forgery
WordPress Simple Mobile URL Redirect Plugin <= 1.7.2 is vulnerable to Cross Site Request Forgery (CSRF)
28RIESGO
abrir ↗Nucleicritical
WordPress GamiPress <= 2.5.7 - SQL Injection
WordPress GamiPress Plugin <= 2.5.7 is vulnerable to SQL Injection
36RIESGO
abrir ↗Nucleihigh
CData RSB Connect v22.0.8336 - Server Side Request Forgery
CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
36RIESGO
abrir ↗Nucleimedium
Squidex <7.4.0 - Cross-Site Scripting
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
28RIESGO
abrir ↗Nucleimedium
mojoPortal 2.7.0.0 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows atta
40RIESGO
abrir ↗Nucleicritical
UserPro <= 5.1.1 - Authentication Bypass
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RIESGO
abrir ↗Nucleicritical
Citrix ShareFile StorageZones Controller - Unauthenticated Remote Code Execution
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RIESGO
abrir ↗Nucleimedium
phpIPAM - 1.6 - Cross-Site Scripting
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter
48RIESGO
abrir ↗Nucleimedium
PMB 7.4.6 - Cross-Site Scripting
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad
18RIESGO
abrir ↗Nucleimedium
PMB 7.4.6 - Open Redirect
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerabil
18RIESGO
abrir ↗Nucleimedium
PMB v7.4.6 - Cross-Site Scripting
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad
18RIESGO
abrir ↗Nucleicritical
Appium Desktop Server - Remote Code Execution
OS Command Injection in appium/appium-desktop
48RIESGO
abrir ↗Nucleicritical
vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP reques
68RIESGO
abrir ↗Nucleicritical
GeoServer OGC Filter - SQL Injection
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir ↗Nucleimedium
WordPress Easy Forms for Mailchimp Plugin < 6.8.9 - Cross-Site Scripting
Easy Forms for Mailchimp < 6.8.9 - Reflected XSS
28RIESGO
abrir ↗Nucleihigh
Apache Druid Kafka Connect - Remote Code Execution
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RIESGO
abrir ↗Nucleicritical
D-Link DIR820LA1_FW105B03 'ping_addr' - OS Command Injection
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a cr
95RIESGO
abrir ↗Nucleimedium
ChurchCRM 4.5.3 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web
28RIESGO
abrir ↗Nucleihigh
Metersphere - Arbitrary File Read
Improper access control to download file in metersphere
48RIESGO
abrir ↗Nucleicritical
Ruckus Wireless Admin - Remote Code Execution
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated
95RIESGO
abrir ↗Nucleicritical
ZoneMinder Snapshots - Command Injection
ZoneMinder vulnerable to Missing Authorization
58RIESGO
abrir ↗Nucleihigh
Lexmark Printers - Command Injection
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
68RIESGO
abrir ↗Nucleimedium
KiviCare WordPress Plugin - Cross-Site Scripting
KiviCare Management System < 3.2.1 - Reflected Cross-Site Scripting
18RIESGO
abrir ↗Nucleihigh
STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2
68RIESGO
abrir ↗Nucleihigh
STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2
61RIESGO
abrir ↗Nucleicritical
Arcserve UDP <= 9.0.6034 - Authentication Bypass
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe
50RIESGO
abrir ↗Nucleihigh
Adobe Coldfusion - Authentication Bypass
CVE-2023-38205 issues | ColdFusion Admin Panel Access
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.