Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleimedium
LocalAI - Partial Local File Read
SSRF and Partial LFI in /models/apply Endpoint in mudler/localai
28RIESGO
abrir
Nucleicritical
Push Notification for Post and BuddyPress <= 1.93 - SQL Injection
Push Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLi
63RIESGO
abrir
Nucleimedium
TrakSYS 11.x.x - Sensitive Data Exposure
Parsec Automation TrackSYS pagedefinition direct request
28RIESGO
abrir
Nucleicritical
PayPlus Payment Gateway < 6.6.9 - SQL Injection
PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi
56RIESGO
abrir
Nucleicritical
WordPress Keydatas ≤ 2.5.2 - Arbitrary File Upload
简数采集器 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload
55RIESGO
abrir
Nucleicritical
NetScaler Console - Sensitive Information Disclosure
Sensitive information disclosure
48RIESGO
abrir
Nucleihigh
LOLLMS WebUI - Absolute Path Traversal
Absolute Path Traversal in parisneo/lollms-webui
36RIESGO
abrir
Nucleicritical
UsersWP <= 1.2.10 - Unauthenticated SQL Injection
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by'
43RIESGO
abrir
Nucleimedium
WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
28RIESGO
abrir
Nucleihigh
User Profile Builder < 3.11.8 - File Upload
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RIESGO
abrir
Nucleicritical
Aimhubio Aim Server 3.19.3 - Arbitrary File Overwrite
Arbitrary File Overwrite and Data Exfiltration in aimhubio/aim
55RIESGO
abrir
Nucleihigh
Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure
Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure
36RIESGO
abrir
Nucleicritical
WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusion
Grow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
63RIESGO
abrir
Nucleimedium
Contact Form 7 Math Captcha <= 2.0.1 - Cross-site Scripting
Contact Form 7 Math Captcha <= 2.0.1 - Reflected XSS
28RIESGO
abrir
Nucleimedium
WP Popups - Information Disclosure
WP Popups – WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure
28RIESGO
abrir
Nucleimedium
Campaign Monitor for WordPress - Information Disclosure
Campaign Monitor for WordPress <= 2.8.15 - Unauthenticated Full Path Disclosure
28RIESGO
abrir
Nucleihigh
Lightdash v0.1024.6 - Server-Side Request Forgery
Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and s
36RIESGO
abrir
Nucleihigh
LiteLLM - Server-Side Request Forgery
SSRF in berriai/litellm
48RIESGO
abrir
Nucleimedium
Netgear-WN604 downloadFile.php - Information Disclosure
Netgear WN604 Web Interface downloadFile.php information disclosure
40RIESGO
abrir
Nucleihigh
WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting
WordPress File Upload < 4.24.8 - Reflected XSS
33RIESGO
abrir
Nucleicritical
WhatsUp Gold HasErrors SQL Injection - Authentication Bypass
CVE-2024-6670CRITICALbajo ataqueransomware
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RIESGO
abrir
Nucleicritical
WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypass
WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability
48RIESGO
abrir
Nucleimedium
WP Content Copy Protection & No Right Click - Open Redirect
WP Content Copy Protection & No Right Click (premium) < 15.3 - Open Redirect
28RIESGO
abrir
Nucleimedium
EasySpider 0.6.2 - Arbitrary File Read
NaiboWang EasySpider HTTP GET Request server.js path traversal
28RIESGO
abrir
Nucleihigh
Social Auto Poster <= 5.3.14 - Stored Cross-Site Scripting
Social Auto Poster <= 5.3.14 - Unauthenticated Stored Cross-Site Scripting
36RIESGO
abrir
Nucleihigh
Calibre <= 7.14.0 Arbitrary File Read
Calibre Arbitrary File Read
48RIESGO
abrir
Nucleicritical
Calibre <= 7.14.0 Remote Code Execution
Calibre Remote Code Execution
85RIESGO
abrir
Nucleihigh
AnythingLLM - Information Disclosure
Exposure of Sensitive Information in mintplex-labs/anything-llm
41RIESGO
abrir
Nucleimedium
SmartSearchWP < 2.4.6 - OpenAI Key Disclosure
SmartSearchWP < 2.4.6 - Unauthenticated OpenAI Key Disclosure
28RIESGO
abrir
Nucleimedium
SmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
SmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
28RIESGO
abrir
anteriorpágina 126 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.