Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8182Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4217 exploits
Nucleicritical
Chartify – WordPress Chart Plugin < 2.9.6 - Local File Inclusion
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
63RIESGO
abrir ↗Nucleicritical
WordPress HTML5 Video Player - SQL Injection
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerabilit
41RIESGO
abrir ↗Nucleimedium
System Dashboard < 2.8.15 - Admin+ Path Traversal
System Dashboard < 2.8.15 - Admin+ Path Traversal
28RIESGO
abrir ↗Nucleicritical
WordPress Ultimate Member 2.1.3 - 2.8.2 – SQL Injection
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗Nucleicritical
WordPress Campress Theme <= 1.35 - Unauthenticated Local File Inclusion
Campress <= 1.35 - Unauthenticated Local File Inclusion
43RIESGO
abrir ↗Nucleihigh
WordPress Plugin MainWP Child - Authentication Bypass
MainWP Child <= 5.3.3 - Missing Authorization to Unauthenticated Privilege Escalation
36RIESGO
abrir ↗Nucleimedium
GPT Academic v1.3.9 - Open Redirect
Open Redirect in binary-husky/gpt_academic
28RIESGO
abrir ↗Nucleicritical
D-Link NAS - Command Injection via Name Parameter
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗Nucleicritical
D-Link NAS - Command Injection via Group Parameter
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗Nucleicritical
Really Simple Security < 9.1.2 - Authentication Bypass
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗Nucleimedium
Stable Diffusion Webui 1.10.0 - Open Redirect
Open Redirect in automatic1111/stable-diffusion-webui
28RIESGO
abrir ↗Nucleimedium
Landray EKP - Path Traversal
Landray EKP sysUiComponent.do delPreviewFile path traversal
28RIESGO
abrir ↗Nucleimedium
Altenergy Power Control Software - SQL Injection
Altenergy Power Control Software status_zigbee get_status_zigbee sql injection
28RIESGO
abrir ↗Nucleicritical
Pandora v7.0NG.777.3 - Remote Code Execution
Command Injection leading to RCE via LDAP Misconfiguration
50RIESGO
abrir ↗Nucleimedium
Event Monster <= 1.4.3 - Information Exposure Via Visitors List Export
Event monster <= 1.4.3 - Information Exposure Via Visitors List Export
28RIESGO
abrir ↗Nucleimedium
idcCMS V1.60 - Cross-Site Scripting
idcCMS classProvCity.php GetCityOptionJs cross site scripting
28RIESGO
abrir ↗Nucleicritical
ProjectSend <= r1605 - Improper Authorization
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir ↗Nucleihigh
KiviCare Clinic & Patient Management System (EHR) <= 3.6.4 - SQL Injection
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection
61RIESGO
abrir ↗Nucleihigh
Download Manager < 3.3.04 - Unauthenticated Arbitrary Shortcode Execution
Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution
36RIESGO
abrir ↗Nucleimedium
Gradio - Server Side Request Forgery
SSRF Vulnerability in gradio-app/gradio
28RIESGO
abrir ↗Nucleimedium
LearnPress < 4.2.7.4 - Course Material - Information Disclosure
LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API
28RIESGO
abrir ↗Nucleihigh
Give WP Plugin < 3.19.0 - Cross-Site Scripting
Give < 3.19.0 - Reflected XSS
28RIESGO
abrir ↗Nucleicritical
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir ↗Nucleimedium
W3 Total Cache < 2.8.2 - Log File Exposure
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
28RIESGO
abrir ↗Nucleihigh
WordPress Collapsing Categories <= 3.0.8 - SQL Injection
Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection
56RIESGO
abrir ↗Nucleimedium
LearnDash LMS < 4.10.3 - Sensitive Information Exposure
LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API
28RIESGO
abrir ↗Nucleimedium
LearnDash LMS < 4.10.2 - Sensitive Information Exposure via assignments
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments
28RIESGO
abrir ↗Nucleimedium
LearnDash LMS < 4.10.2 - Sensitive Information Exposure
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.