Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleicritical
WP Directory Kit <= 1.4.4 - Authentication Bypass
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RIESGO
abrir
Nucleimedium
Responsive Pricing Table <= 5.1.12 - Cross-Site Scripting
Responsive Pricing Table <= 5.1.12 - Authenticated (Author+) Stored Cross-Site Scripting
28RIESGO
abrir
Nucleicritical
Advanced Custom Fields Extended < 0.9.2 - Remote Code Execution
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RIESGO
abrir
Nucleihigh
IP2Location Country Blocker < 2.38.9 - Unauthenticated Information Disclosure
IP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init Function
36RIESGO
abrir
Nucleicritical
WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL Injection
CBX Bookmark & Favorite <= 2.0.4 - Authenticated (Subscriber+) SQL Injection via `orderby` Parameter
28RIESGO
abrir
Nucleicritical
WordPress Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Remote Code Execution
Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Unauthenticated Remote Code Execution
43RIESGO
abrir
Nucleihigh
Yoco Payments <= 3.8.8 - Path Traversal
Yoco Payments <= 3.9.0 - Unauthenticated Arbitrary File Read
36RIESGO
abrir
Nucleimedium
WP Directory Kit < 1.5.0 - Unauthenticated Email Exposure
WP Directory Kit <= 1.4.9 - Unauthenticated Email Exposure via wdk_public_action
28RIESGO
abrir
Nucleimedium
LearnPress < 4.3.2 - Broken Access Control
LearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure
28RIESGO
abrir
Nucleihigh
Team WordPress Plugin (TLP Team) <= 5.0.9 - SQL Injection
Team < 5.0.11 - Unauthenticated SQLi
36RIESGO
abrir
Nucleimedium
Premium Addons for Elementor - Unauthenticated Information Disclosure
Premium Addons for Elementor <= 4.11.53 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'get_template_content'
28RIESGO
abrir
Nucleihigh
Payara Server - Cross-Site Scripting
Admin Account Takeover via malicious URL payload
36RIESGO
abrir
Nucleihigh
WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File
Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File
36RIESGO
abrir
Nucleihigh
D-Link DIR-803 - Authentication Bypass
D-Link DIR-803 Configuration getcfg.php information disclosure
28RIESGO
abrir
Nucleicritical
Gladinet CentreStack & Triofox - Hardcoded Credentials
CVE-2025-14611HIGHbajo ataque
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RIESGO
abrir
Nucleimedium
WordPress Widgets for Social Photo Feed <= 1.8 - Information Disclosure
Widgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpoints
28RIESGO
abrir
Nucleicritical
Sangfor OSM - Arbitrary File Upload
Sangfor Operation and Maintenance Management System common.jsp unrestricted upload
28RIESGO
abrir
Nucleicritical
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RIESGO
abrir
Nucleimedium
EasyCVR <=2.1.2 - Information Disclosure
Anhui Xufan Information Technology EasyCVR getbaseconfig information disclosure
28RIESGO
abrir
Nucleicritical
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RIESGO
abrir
Nucleihigh
Pichome 2.1.0 - Arbitrary File Read
zyx0814 Pichome index.php path traversal
28RIESGO
abrir
Nucleicritical
Ingress-Nginx Controller - Remote Code Execution
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
Nucleicritical
WordPress JobWP Plugin <= 2.3.9 - SQL Injection
JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin <= 2.3.9 - Unauthenticated SQL Injection
36RIESGO
abrir
Nucleihigh
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RIESGO
abrir
Nucleicritical
Cisco IOS XE WLC - Arbitrary File Upload
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de
68RIESGO
abrir
Nucleicritical
Cisco ISE - Remote Code Execution
CVE-2025-20281CRITICALbajo ataque
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RIESGO
abrir
Nucleimedium
Cisco Secure Firewall ASA & FTD - Authentication Bypass
CVE-2025-20362MEDIUMbajo ataque
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar
100RIESGO
abrir
Nucleihigh
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
36RIESGO
abrir
Nucleimedium
JoomlaUX JUX Real Estate 3.4.0 - Reflected XSS
JoomlaUX JUX Real Estate realties cross site scripting
28RIESGO
abrir
Nucleimedium
Mage AI - Insecure Default Authentication Setup
Mage AI insecure default initialization of resource
28RIESGO
abrir
anteriorpágina 130 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.