Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
4193 exploits
Nucleimedium
All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure
All-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error Logs
28RIESGO
abrir
Nucleicritical
WP Time Capsule Plugin - Remote Code Execution
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir
Nucleicritical
Mlflow < 2.17.0 - Local File Inclusion
Path Traversal in mlflow/mlflow
36RIESGO
abrir
Nucleicritical
Riello Netman 204 - SQL Injection
SQL Injection
50RIESGO
abrir
Nucleimedium
Keycloak - Open Redirect
Keycloak: vulnerable redirect uri validation results in open redirec
28RIESGO
abrir
Nucleicritical
LatePoint <= 5.0.11 - SQL Injection
LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection
43RIESGO
abrir
Nucleicritical
LatePoint <= 5.0.12 - Authentication Bypass
LatePoint <= 5.0.12 - Authentication Bypass
43RIESGO
abrir
Nucleicritical
Ivanti Cloud Services Appliance - Path Traversal
CVE-2024-8963CRITICALbajo ataque
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RIESGO
abrir
Nucleimedium
123Solar 1.8.4.5 - Cross-Site Scripting
jeanmarc77 123solar detailed.php cross site scripting
28RIESGO
abrir
Nucleicritical
pgAdmin 4 - Authentication Bypass
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RIESGO
abrir
Nucleicritical
WordPress File Upload <= 4.24.11 - Arbitrary File Read
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RIESGO
abrir
Nucleihigh
WP Popup Builder Popup Forms and Marketing Lead Generation <= 1.3.5 - Arbitrary Shortcode Execution
WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add
48RIESGO
abrir
Nucleimedium
Rank Math SEO < 1.0.229 - Unauthenticated User and Term Metadata Insert/Update/Deletion
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete
28RIESGO
abrir
Nucleicritical
TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
63RIESGO
abrir
Nucleihigh
Automation By Autonami < 3.3.0 - SQL Injection
Automation By Autonami < 3.3.0 - Unauthenticated SQLi
36RIESGO
abrir
Nucleicritical
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
43RIESGO
abrir
Nucleicritical
GutenKit <= 2.1.0 - Arbitrary File Upload
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
Nucleicritical
Grafana Post-Auth DuckDB - SQL Injection To File Read
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
Nucleihigh
Polyaxon - Unauthenticated Directory Traversal
Directory Traversal in polyaxon/polyaxon
36RIESGO
abrir
Nucleicritical
PaloAlto Networks Expedition - Remote Code Execution
CVE-2024-9463CRITICALbajo ataque
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RIESGO
abrir
Nucleihigh
Palo Alto Expedition - SQL Injection
CVE-2024-9465CRITICALbajo ataque
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RIESGO
abrir
Nucleihigh
PAN-OS Management Web Interface - Command Injection
CVE-2024-9474MEDIUMbajo ataqueransomware
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
Nucleihigh
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Remote Code Execution
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
61RIESGO
abrir
Nucleimedium
Danswer - Insecure Direct Object Reference
IDOR in danswer-ai/danswer
28RIESGO
abrir
Nucleicritical
Triofox - Improper Access Control
CVE-2025-12480CRITICALbajo ataque
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to init
95RIESGO
abrir
Nucleimedium
SureForms <= 1.13.1 - Sensitive Information Exposure
SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure
28RIESGO
abrir
Nucleihigh
WordPress Bookit < 2.5.1 - Unauthenticated Stripe Settings Update
Bookit < 2.5.1 – Unauthenticated Settings Update
28RIESGO
abrir
Nucleicritical
JSONPath Plus < 10.3.0 - Remote Code Execution
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RIESGO
abrir
Nucleimedium
Plugin Oficial – Getnet para WooCommerce <= 1.8.0 - Cross-Site Scripting
Plugin Oficial – Getnet para WooCommerce <= 1.7.3 - Unauthenticated Reflected XSS
28RIESGO
abrir
Nucleihigh
WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection
WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection via select_2_ajax() Function
36RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.