Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8182Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4217 exploits
Nucleicritical
Prodigy Commerce <= 3.3.0 - Local File Inclusion
Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]
63RIESGO
abrir ↗Nucleicritical
Ivanti Sentry - OS Command Injection
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir ↗Nucleicritical
Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account Takeover
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
63RIESGO
abrir ↗Nucleihigh
YMC Filter WordPress - Unauthenticated Post Disclosure
YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure
56RIESGO
abrir ↗Nucleihigh
Django RasterField - SQL Injection
Potential SQL injection via raster lookups on PostGIS
28RIESGO
abrir ↗Nucleimedium
URL Shortify <= 1.12.1 - Open Redirect
URL Shortify <= 1.12.1 - Unauthenticated Open Redirect via 'redirect_to' Parameter
28RIESGO
abrir ↗Nucleimedium
Frontend Post Submission Manager Lite <= 1.2.7 - Open Redirect
Frontend Post Submission Manager Lite <= 1.2.7 - Unauthenticated Open Redirect via 'requested_page' Parameter
28RIESGO
abrir ↗Nucleicritical
WordPress midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload
midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action
43RIESGO
abrir ↗Nucleimedium
WordPress 3D FlipBook <= 1.16.17 - Information Disclosure
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated Private/Draft Flipbook Data Exposure
28RIESGO
abrir ↗Nucleicritical
WPvivid Backup & Migration <= 0.9.123 - Arbitrary File Upload
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir ↗Nucleihigh
Video Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature Generation
Video Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature Generation
36RIESGO
abrir ↗Nucleihigh
WPBot <= 8.4.9 - Cross-Site Scripting
WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter
36RIESGO
abrir ↗Nucleicritical
WordPress Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗Nucleicritical
WordPress User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
68RIESGO
abrir ↗Nucleimedium
WP Hotel Booking <= 2.3.2 - Cross-Site Scripting
WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter
28RIESGO
abrir ↗Nucleihigh
WP Responsive Images <= 1.0 - Arbitrary File Read
WP Responsive Images <= 1.0 - Unauthenticated Path Traversal to Arbitrary File Read via src
36RIESGO
abrir ↗Nucleicritical
wpForo Forum <= 2.4.14 - SQL Injection
wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection
56RIESGO
abrir ↗Nucleihigh
Ivanti Endpoint Manager - Authentication Bypass
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to
88RIESGO
abrir ↗Nucleimedium
LeadConnector < 3.0.22 - Unauthenticated Arbitrary Data Write
LeadConnector < 3.0.22 - Unauthenticated Rest Call
28RIESGO
abrir ↗Nucleimedium
WPBookit <= 1.0.8 - Unauthenticated Customer Information Disclosure
WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure
28RIESGO
abrir ↗Nucleicritical
Cisco Secure Firewall Management Center - Authentication Bypass
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti
55RIESGO
abrir ↗Nucleihigh
Mail Mint < 1.19.5 - Unauthenticated Email Disclosure
Mail Mint < 1.19.5 - Unauthenticated Emails Disclosure
36RIESGO
abrir ↗Nucleimedium
MajorDoMo - Cross-Site Scripting
MajorDoMo Reflected Cross-Site Scripting in command.php
28RIESGO
abrir ↗Nucleihigh
MindsDB - Remote Code Execution
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RIESGO
abrir ↗Nucleimedium
Changedetection.io RSS Single Watch - Cross-Site Scripting
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
28RIESGO
abrir ↗Nucleihigh
OpenCATS - Command Injection
OpenCATS PHP Code Injection via installer AJAX endpoint
68RIESGO
abrir ↗Nucleihigh
Gitea Container Registry - Unauthorized Private Image Access
Gitea Composer package source links use insufficient permission checks
68RIESGO
abrir ↗Nucleihigh
mcp-atlassian < 0.17.0 - Server-Side Request Forgery
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
41RIESGO
abrir ↗Nucleihigh
Piwigo < 16.3.0 - Unauthenticated Information Disclosure via History API
Piwigo: Unauthenticated Information Disclosure via pwg.history.search API
36RIESGO
abrir ↗Nucleicritical
Nginx UI < 2.3.3 - Information Disclosure
Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.