Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleihigh
Ultimate Addons for Elementor <= 1.24.1 - Registration Bypass
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the w
36RIESGO
abrir ↗Nucleihigh
Artica Proxy Community Edition <4.30.000000 - Local File Inclusion
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parame
30RIESGO
abrir ↗Nucleicritical
Netsweeper <=6.4.3 - Python Code Injection
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain
40RIESGO
abrir ↗Nucleimedium
Contentful <=2020-05-21 - Cross-Site Scripting
Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.p
18RIESGO
abrir ↗Nucleihigh
Grafana 3.0.1-7.0.1 - Server-Side Request Forgery
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows
60RIESGO
abrir ↗Nucleihigh
Microweber <1.1.20 - Information Disclosure
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose
23RIESGO
abrir ↗Nucleimedium
Bitrix24 <=20.0.0 - Cross-Site Scripting
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/
18RIESGO
abrir ↗Nucleicritical
rConfig 3.9 - Authentication Bypass(Admin Login)
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account cr
40RIESGO
abrir ↗Nucleicritical
wpDiscuz <= 5.3.5 - SQL Injection
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute
23RIESGO
abrir ↗Nucleihigh
WordPress acf-to-rest-api <=3.1.0 - Insecure Direct Object Reference
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object r
23RIESGO
abrir ↗Nucleimedium
Extreme Management Center 8.4.1.24 - Cross-Site Scripting
Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
18RIESGO
abrir ↗Nucleihigh
Artica Pandora FMS 7.44 - Remote Code Execution
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
40RIESGO
abrir ↗Nucleihigh
Intelbras TIP 200/200 LITE/300 - Local File Inclusion
Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?pag
18RIESGO
abrir ↗Nucleicritical
Airflow Experimental <1.10.11 - REST API Auth Bypass
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RIESGO
abrir ↗Nucleimedium
Apache Kylin - Exposed Configuration File
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.
40RIESGO
abrir ↗Nucleicritical
Apache Unomi <1.5.2 - Remote Code Execution
Remote Code Execution in Apache Unomi
50RIESGO
abrir ↗Nucleimedium
Apache APISIX - Insufficiently Protected Credentials
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the
40RIESGO
abrir ↗Nucleicritical
WordPress PayPal Pro <1.1.65 - SQL Injection
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
40RIESGO
abrir ↗Nucleihigh
NexusDB <4.50.23 - Local File Inclusion
NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
23RIESGO
abrir ↗Nucleihigh
D-Link DSL 2888a - Authentication Bypass/Remote Command Execution
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attac
18RIESGO
abrir ↗Nucleicritical
WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection
48RIESGO
abrir ↗Nucleimedium
OX Appsuite - Cross-Site Scripting
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
18RIESGO
abrir ↗Nucleicritical
OsTicket < 1.14.3 - Server Side Request Forgery
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RIESGO
abrir ↗Nucleimedium
Quixplorer <=2.4.1 - Cross-Site Scripting
Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied
28RIESGO
abrir ↗Nucleimedium
Cute Editor for ASP.NET 6.4 - Cross-Site Scripting
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user
18RIESGO
abrir ↗Nucleimedium
QCube Cross-Site-Scripting
A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQ
18RIESGO
abrir ↗Nucleihigh
PHP-Fusion 9.03.50 - Remote Code Execution
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RIESGO
abrir ↗Nucleihigh
D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir ↗Nucleimedium
Pritunl VPN Server 1.29.2145.25 - Username Enumeration
Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Ini
18RIESGO
abrir ↗Nucleicritical
WordPress File Manager Plugin - Remote Code Execution
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.