Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleicritical
Shield Security WP Plugin <= 18.5.9 - Local File Inclusion
Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion
55RIESGO
abrir ↗Nucleihigh
GitLab - Account Takeover via Password Reset
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗Nucleimedium
WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection
WeiYe-Jing datax-web HTTP POST Request killJob os command injection
28RIESGO
abrir ↗Nucleihigh
WordPress BackWPup < 4.0.4 - Backup File Disclosure
BackWPup < 4.0.4 - Unauthenticated Backup Download
36RIESGO
abrir ↗Nucleihigh
JetBackup <= 2.0.9.7 - Sensitive Information Exposure via Directory Listing
JetBackup < 2.0.9.9 - Directory Listing Exposing Backups
36RIESGO
abrir ↗Nucleimedium
System Dashboard < 2.8.10 - Cross-Site Scripting
System Dashboard < 2.8.10 - XSS via Header Injection
28RIESGO
abrir ↗Nucleihigh
Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read
Ozeki SMS Gateway <= 10.3.208 Unauthenticated Arbitrary File Read
36RIESGO
abrir ↗Nucleicritical
JS Help Desk <= 2.8.2 - SQL Injection
JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie
36RIESGO
abrir ↗Nucleicritical
PAN-OS Management Web Interface - Authentication Bypass
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir ↗Nucleicritical
SpiderFlow Crawler Platform - Remote Code Execution
spider-flow FunctionController.java FunctionService.saveFunction code injection
33RIESGO
abrir ↗Nucleicritical
Github Enterprise Authenticated Remote Code Execution
Unsafe Reflection in Github Enterprise Server leading to Command Injection
58RIESGO
abrir ↗Nucleicritical
Fortra GoAnywhere MFT - Authentication Bypass
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir ↗Nucleimedium
EventON (Free < 2.2.8, Premium < 4.5.5) - Information Disclosure
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RIESGO
abrir ↗Nucleimedium
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
28RIESGO
abrir ↗Nucleihigh
Ncast busiFacade - Remote Command Execution
Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure
60RIESGO
abrir ↗Nucleimedium
Travelpayouts <= 1.1.16 - Open Redirect
Travelpayouts <= 1.1.15 - Open Redirect
28RIESGO
abrir ↗Nucleicritical
Likeshop < 2.5.7.20210311 - Arbitrary File Upload
Likeshop HTTP POST Request File.php userFormImage unrestricted upload
78RIESGO
abrir ↗Nucleimedium
WordPress Simple Job Board - Unauthorized Data Access
Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
28RIESGO
abrir ↗Nucleicritical
Monsta FTP <= 2.11.2 - Unauthenticated Remote Code Execution
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗Nucleicritical
SawtoothSoftware Lighthouse Studio < 9.16.14 - Pre-Auth Remote Code Execution
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RIESGO
abrir ↗Nucleihigh
Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials
Sitecore XM and XP Hardcoded Credentials
48RIESGO
abrir ↗Nucleimedium
Ocean Extra <= 2.4.6 - Unauthenticated Shortcode Execution
Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution
28RIESGO
abrir ↗Nucleihigh
Contact Form 7 Drag and Drop Multiple File Upload - Arbitrary File Upload
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RIESGO
abrir ↗Nucleicritical
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RIESGO
abrir ↗Nucleicritical
Dell UnityVSA < 5.5 - Remote Command Injection
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('
68RIESGO
abrir ↗Nucleihigh
Eveo URVE Web Manager - Server-Side Request Forgery
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side
36RIESGO
abrir ↗Nucleicritical
HPE OneView - Remote Code Execution
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir ↗Nucleihigh
MeteoBridge <= 6.1 - Remote Code Execution
Arbitrary Command Injection in Smartbedded MeteoBridge
88RIESGO
abrir ↗Nucleicritical
Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command Injection
Unauthenticated Arbitrary Command Injection in Evertz SDVN
65RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.