Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8150Nuclei 4193Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4191 exploits
Nucleimedium
NewsTicker <= 1.0 - Reflected Cross-Site Scripting
News List <= 1.0 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
Post Sync Plugin <= 1.1 - Cross-Site Scripting
Post Sync <= 1.1 - Reflected XSS
28RIESGO
abrir ↗Nucleihigh
Themes Coder Ecommerce <= 1.3.4 - SQL Injection
Themes Coder <= 1.3.4 - Unauthenticated SQLi
36RIESGO
abrir ↗Nucleimedium
MemberSpace WordPress - Cross-Site Scripting
MemberSpace – Membership Plugin and Paid Subscriptions < 2.1.14 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
Relevanssi (A Better Search) <= 4.22.0 - Query Log Export
Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export
40RIESGO
abrir ↗Nucleimedium
WordPress SEO Tools Plugin 4.0.7 - Cross-Site Scripting
SEO Tools <= 4.0.7 - Reflected XSS
28RIESGO
abrir ↗Nucleihigh
WPMobile.App <= 11.56 - Open Redirect
WPMobile.App <= 11.56 - Open Redirect via 'redirect' Parameter
36RIESGO
abrir ↗Nucleicritical
St. Joe ERP system - SQL Injection
St. Joe ERP System SingleRowQueryConverter SQL Injection
63RIESGO
abrir ↗Nucleimedium
Studiocart <= 2.9.0 - Cross-Site Scripting
Studiocart <= 2.9.0 - Reflected XSS
36RIESGO
abrir ↗Nucleihigh
Mlflow < 2.9.2 - Path Traversal
Path Traversal Vulnerability in mlflow/mlflow
36RIESGO
abrir ↗Nucleicritical
MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
85RIESGO
abrir ↗Nucleihigh
Gradio 4.3-4.12 - Local File Read
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RIESGO
abrir ↗Nucleicritical
NotificationX <= 2.8.2 - SQL Injection
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir ↗Nucleicritical
ConnectWise ScreenConnect 23.9.7 - Authentication Bypass
Authentication bypass using an alternate path or channel
100RIESGO
abrir ↗Nucleihigh
Gradio > 4.19.1 UploadButton - Path Traversal
Local File Inclusion in gradio-app/gradio
58RIESGO
abrir ↗Nucleihigh
Tutor LMS <= 2.1.10 - SQL Injection
Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection
36RIESGO
abrir ↗Nucleimedium
Cisco Finesse - Server-Side Request Forgery (SSRF)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t
61RIESGO
abrir ↗Nucleicritical
Cisco SSM On-Prem <= 8-202206 - Password Reset Account Takeover
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
85RIESGO
abrir ↗Nucleicritical
Hardcoded Admin Credentials For Cisco Smart Licensing Utility API
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a
95RIESGO
abrir ↗Nucleihigh
Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive inf
48RIESGO
abrir ↗Nucleihigh
Artica Proxy - Unauthenticated LFI
Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
68RIESGO
abrir ↗Nucleihigh
Adobe ColdFusion - Arbitrary File Read
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir ↗Nucleihigh
Oracle Retail Xstore Suite - Pre-authenticated Path Traversal
Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported
36RIESGO
abrir ↗Nucleimedium
Fujian Kelixin Communication - Command Injection
Fujian Kelixin Communication Command and Dispatch Platform pwd_update.php sql injection
28RIESGO
abrir ↗Nucleihigh
Avid NEXIS Agent - Arbitrary File Read
Authenticated Arbitrary File Read affecting Avid NEXIS
36RIESGO
abrir ↗Nucleihigh
ReCrystallize Server - Authentication Bypass
ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind
48RIESGO
abrir ↗Nucleicritical
InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗Nucleihigh
SOPlanning - Remote Code Execution
Remote Code Execution through File Upload in SOPlanning before 1.52.02
43RIESGO
abrir ↗Nucleicritical
TeamCity < 2023.11.4 - Authentication Bypass
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.