Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.666exploits catalogados
32.032CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.896GitHub PoC 13.204VulnCheck XDB 8127Nuclei 4191Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4191 exploits
Nucleihigh
Pascom CPS - Local File Inclusion
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Pho
23RIESGO
abrir ↗Nucleimedium
Sourcecodester Car Rental Management System 1.0 - Stored Cross-Site Scripting
Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter
18RIESGO
abrir ↗Nucleimedium
Vehicle Service Management System - Stored Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Sec
18RIESGO
abrir ↗Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List
18RIESGO
abrir ↗Nucleimedium
ehicle Service Management System 1.0 - Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List
18RIESGO
abrir ↗Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List S
18RIESGO
abrir ↗Nucleimedium
Vehicle Service Management System 1.0 - Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the
18RIESGO
abrir ↗Nucleihigh
webp_server_go 0.4.0 - Path Traversal
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi
18RIESGO
abrir ↗Nucleihigh
Ligeo Archives Ligeo Basics - Server Side Request Forgery
Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacke
18RIESGO
abrir ↗Nucleihigh
AntD Admin - Sensitive Information Disclosure
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the
18RIESGO
abrir ↗Nucleimedium
D-Link DIR850 ET850-1.08TRb03 - Open Redirect
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RIESGO
abrir ↗Nucleihigh
D-Link DAP-1620 - Local File Inclusion
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RIESGO
abrir ↗Nucleimedium
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RIESGO
abrir ↗Nucleihigh
Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RIESGO
abrir ↗Nucleihigh
Telesquare TLR-2855KS6 - Arbitrary File Creation
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
43RIESGO
abrir ↗Nucleicritical
WordPress BadgeOS <=3.7.0 - SQL Injection
BadgeOS <= 3.7.0 - Unauthenticated SQLi
23RIESGO
abrir ↗Nucleihigh
Webmin <1.990 - Improper Access Control
Improper Access Control to Remote Code Execution in webmin/webmin
78RIESGO
abrir ↗Nucleicritical
WordPress WP Video Gallery <=1.7.1 - SQL Injection
WP Video Gallery <= 1.7.1 - Unauthenticated SQLi
18RIESGO
abrir ↗Nucleicritical
WordPress Best Books <=2.6.3 - SQL Injection
Bestbooks <= 2.6.3 - Unauthenticated SQLi
18RIESGO
abrir ↗Nucleicritical
SpeakOut Email Petitions < 2.14.15.1 - SQL Injection
SpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLi
18RIESGO
abrir ↗Nucleimedium
UpdraftPlus < 1.22.9 - Cross-Site Scripting
UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting
18RIESGO
abrir ↗Nucleicritical
WordPress ARPrice <3.6.1 - SQL Injection
ARPrice Lite < 3.6.1 - Unauthenticated SQLi
23RIESGO
abrir ↗Nucleimedium
nitely/spirit 0.12.3 - Open Redirect
Multiple Open Redirect in nitely/spirit
28RIESGO
abrir ↗Nucleimedium
Gogs <0.12.5 - Server-Side Request Forgery
Server-Side Request Forgery (SSRF) in gogs/gogs
28RIESGO
abrir ↗Nucleimedium
WordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site Scripting
Gmedia Photo Gallery < 1.20.0 - Admin+ Stored Cross-Site Scripting
18RIESGO
abrir ↗Nucleimedium
Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting
Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting
18RIESGO
abrir ↗Nucleicritical
Member Hero <=1.0.9 - Remote Code Execution
Member Hero <= 1.0.9 - Unauthenticated RCE
18RIESGO
abrir ↗Nucleimedium
Header Footer Code Manager < 1.1.24 - Cross-Site Scripting
Header Footer Code Manager < 1.1.24 - Reflected Cross-Site Scripting
18RIESGO
abrir ↗Nucleimedium
Microweber < 1.2.12 - Stored Cross-Site Scripting
Cross-site Scripting (XSS) - Stored in microweber/microweber
28RIESGO
abrir ↗Nucleicritical
WordPress Order Listener for WooCommerce <3.2.2 - SQL Injection
Order Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi
18RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.