Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleihigh
XWiki < 4.10.15 - Sensitive Information Disclosure
XWiki Platform Solr search discloses password hashes of all users
58RIESGO
abrir ↗Nucleimedium
XWiki < 4.10.15 - Email Disclosure
XWiki Platform Solr search discloses email addresses of users
40RIESGO
abrir ↗Nucleicritical
D-Link D-View 8 v2.0.1.28 - Authentication Bypass
Authentication Bypass in D-Link D-View 8
55RIESGO
abrir ↗Nucleicritical
JS Help Desk <= 2.8.1 - SQL Injection
WordPress JS Help Desk – Best Help Desk & Support Plugin <= 2.8.1 is vulnerable to SQL Injection
63RIESGO
abrir ↗Nucleimedium
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
28RIESGO
abrir ↗Nucleicritical
MajorDoMo thumb.php - OS Command Injection
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RIESGO
abrir ↗Nucleihigh
Apache OFBiz < 18.12.11 - Server Side Request Forgery
Apache OFBiz: Arbitrary file properties reading and SSRF attack
30RIESGO
abrir ↗Nucleicritical
Jordy Meow AI Engine - Unrestricted File Upload
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RIESGO
abrir ↗Nucleihigh
Gradio Hugging Face - Local File Inclusion
Make the `/file` secure against file traversal attacks
28RIESGO
abrir ↗Nucleimedium
Seriously Simple Podcasting < 3.0.0 - Information Disclosure
Seriously Simple Podcasting < 3.0.0 - Unauthenticated Administrator Email Disclosure
28RIESGO
abrir ↗Nucleihigh
Prime Mover < 1.9.3 - Sensitive Data Exposure
Prime Mover < 1.9.3 - Directory Listing to Sensitive Data Exposure
48RIESGO
abrir ↗Nucleicritical
Citrix Netscaler ADC & Gateway - Out-Of-Bounds Memory Read
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Un
78RIESGO
abrir ↗Nucleicritical
Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir ↗Nucleihigh
LearnPress <= 4.2.5.7 - SQL Injection
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
75RIESGO
abrir ↗Nucleimedium
Mlflow - Cross-Site Scripting
Reflected XSS via Content-Type Header in mlflow/mlflow
28RIESGO
abrir ↗Nucleimedium
WordPress FastDup <= 2.1.9 Sensitive Information Exposure - Directory Listing
FastDup – Fastest WordPress Migration & Duplicator < 2.2 - Directory Listing to Account Takeover and Sensitive Data Exposure
28RIESGO
abrir ↗Nucleicritical
Essential Blocks < 4.4.3 - Local File Inclusion
Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion
75RIESGO
abrir ↗Nucleicritical
LearnPress < 4.2.5.8 - Remote Code Execution
LearnPress <= 4.2.5.7 - Command Injection
56RIESGO
abrir ↗Nucleihigh
Hongjing e-HR 2020 - SQL Injection
Hongjing e-HR Login Interface loadhistroyorgtree sql injection
36RIESGO
abrir ↗Nucleimedium
WP Go Maps (formerly WP Google Maps) < 9.0.29 - Cross-Site Scripting
WP Go Maps (formerly WP Google Maps) <= 9.0.28 - Reflected Cross-Site Scripting
28RIESGO
abrir ↗Nucleicritical
WordPress WP Clone <= 2.4.2 - Database Backup Exposure
Clone < 2.4.3 - Unauthenticated Backup Download
36RIESGO
abrir ↗Nucleimedium
Payment Gateway for Telcell < 2.0.4 - Open Redirect
Payment Gateway for Telcell <= 2.0.1 - Unauthenticated Open Redirect
28RIESGO
abrir ↗Nucleicritical
WordPress File Manager <= 7.2.1 - Directory Traversal
File Manager And File Manager Pro (Multiple Versions) - Directory Traversal
43RIESGO
abrir ↗Nucleicritical
WordPress POST SMTP Mailer <= 2.8.7 - Authorization Bypass
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir ↗Nucleicritical
Hikvision IP ping.php - Command Execution
Hikvision Intercom Broadcasting System ping.php os command injection
70RIESGO
abrir ↗Nucleihigh
Mlflow <2.9.2 - Path Traversal
Path Traversal: '\..\filename' in mlflow/mlflow
58RIESGO
abrir ↗Nucleicritical
Better Search Replace < 1.4.5 - PHP Object Injection
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
68RIESGO
abrir ↗Nucleimedium
WP Recipe Maker <= 9.1.0 - Reflected XSS via Referer Header
WP Recipe Maker <= 9.1.0 - Reflected Cross-Site Scripting via Referer
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.