Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4202 exploits
Nucleimedium
Web2py URL - Open Redirect
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirec
28RIESGO
abrir ↗Nucleicritical
KubePi JwtSigKey - Admin Authentication Bypass
KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT token
55RIESGO
abrir ↗Nucleihigh
KubePi <= v1.6.4 LoginLogsSearch - Unauthorized Access
KubePi is vulnerable to missing authorization
36RIESGO
abrir ↗Nucleicritical
KubeOperator Foreground `kubeconfig` - File Download
KubeOperator is vulnerable to unauthorized access to system API
48RIESGO
abrir ↗Nucleicritical
Atlassian Confluence - Privilege Escalation
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗Nucleicritical
Atlassian Confluence Server - Improper Authorization
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir ↗Nucleicritical
Atlassian Confluence - Remote Code Execution
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗Nucleihigh
WordPress Product Addons & Fields for WooCommerce < 32.0.7 - Cross-Site Scripting
Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting
18RIESGO
abrir ↗Nucleihigh
SecurePoint UTM 12.x Session ID Leak
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid infor
36RIESGO
abrir ↗Nucleihigh
Strapi Versions <=4.5.5 - SSTI to Remote Code Execution
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RIESGO
abrir ↗Nucleimedium
Tiempo.com <= 0.1.2 - Cross-Site Scripting
Tiempo.com <= 0.1.2 - Reflected XSS
18RIESGO
abrir ↗Nucleihigh
Strapi Versions <=4.5.6 - Authentication Bypass
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login pro
36RIESGO
abrir ↗Nucleimedium
Securepoint UTM - Leaking Remote Memory Contents
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information dis
28RIESGO
abrir ↗Nucleihigh
SugarCRM Unauthenticated - Remote Code Execution
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because o
100RIESGO
abrir ↗Nucleihigh
Cellinx NVT Web Server - Local File Disclosure
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFi
38RIESGO
abrir ↗Nucleimedium
wpForo Forum <= 2.1.8 - Cross-Site Scripting
wpForo Forum < 2.1.9 - Reflected Cross-Site Scripting
18RIESGO
abrir ↗Nucleimedium
Art Gallery Management System Project v1.0 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RIESGO
abrir ↗Nucleicritical
SolarView Compact 6.00 - OS Command Injection
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir ↗Nucleicritical
WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir ↗Nucleicritical
WordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL Injection
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection
48RIESGO
abrir ↗Nucleimedium
Quick Event Manager < 9.7.5 - Cross-Site Scripting
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability
28RIESGO
abrir ↗Nucleicritical
Jms Blog - SQL Injection
PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
55RIESGO
abrir ↗Nucleihigh
Appwrite <=1.2.1 - Server-Side Request Forgery
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favic
48RIESGO
abrir ↗Nucleimedium
Request-Baskets <= 1.2.1 - Server Side Request Forgery
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir ↗Nucleihigh
GDidees CMS v3.9.1 - Arbitrary File Download
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RIESGO
abrir ↗Nucleimedium
OpenCATS - Open Redirect
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET pa
28RIESGO
abrir ↗Nucleicritical
MStore API <= 3.9.2 - Authentication Bypass
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir ↗Nucleicritical
MStore API <= 3.9.1 - Authentication Bypass
MStore API <= 3.9.1 - Authentication Bypass
43RIESGO
abrir ↗Nucleicritical
PaperCut - Unauthenticated Remote Code Execution
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.