Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.814exploits catalogados
32.125CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.248VulnCheck XDB 8150Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4193 exploits
Nucleicritical
SPIP BigUp Plugin - Remote Code Execution
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir ↗Nucleicritical
LearnPress < 4.2.7.1 - SQL Injection
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RIESGO
abrir ↗Nucleicritical
LearnPress < 4.2.7.1 - SQL Injection
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RIESGO
abrir ↗Nucleihigh
WordPress TS Poll < 2.4.0 - SQL Injection
TS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection
36RIESGO
abrir ↗Nucleilow
Z-Downloads < 1.11.7 - Cross-Site Scripting
Z-Downloads < 1.11.7 - Admin+ Stored XSS via SVG Upload
63RIESGO
abrir ↗Nucleihigh
Keycloak - SAML Core Package Signature Validation Flaw
Keycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloak
36RIESGO
abrir ↗Nucleihigh
WebIQ 2.15.9 - Directory Traversal
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
68RIESGO
abrir ↗Nucleimedium
All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure
All-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error Logs
28RIESGO
abrir ↗Nucleicritical
WP Time Capsule Plugin - Remote Code Execution
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗Nucleimedium
Keycloak - Open Redirect
Keycloak: vulnerable redirect uri validation results in open redirec
28RIESGO
abrir ↗Nucleicritical
LatePoint <= 5.0.11 - SQL Injection
LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection
43RIESGO
abrir ↗Nucleicritical
LatePoint <= 5.0.12 - Authentication Bypass
LatePoint <= 5.0.12 - Authentication Bypass
43RIESGO
abrir ↗Nucleicritical
Ivanti Cloud Services Appliance - Path Traversal
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RIESGO
abrir ↗Nucleimedium
123Solar 1.8.4.5 - Cross-Site Scripting
jeanmarc77 123solar detailed.php cross site scripting
28RIESGO
abrir ↗Nucleicritical
pgAdmin 4 - Authentication Bypass
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RIESGO
abrir ↗Nucleicritical
WordPress File Upload <= 4.24.11 - Arbitrary File Read
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RIESGO
abrir ↗Nucleihigh
WP Popup Builder Popup Forms and Marketing Lead Generation <= 1.3.5 - Arbitrary Shortcode Execution
WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add
48RIESGO
abrir ↗Nucleimedium
Rank Math SEO < 1.0.229 - Unauthenticated User and Term Metadata Insert/Update/Deletion
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete
28RIESGO
abrir ↗Nucleicritical
TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
63RIESGO
abrir ↗Nucleihigh
Automation By Autonami < 3.3.0 - SQL Injection
Automation By Autonami < 3.3.0 - Unauthenticated SQLi
36RIESGO
abrir ↗Nucleicritical
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
43RIESGO
abrir ↗Nucleicritical
GutenKit <= 2.1.0 - Arbitrary File Upload
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗Nucleicritical
Grafana Post-Auth DuckDB - SQL Injection To File Read
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir ↗Nucleihigh
Polyaxon - Unauthenticated Directory Traversal
Directory Traversal in polyaxon/polyaxon
36RIESGO
abrir ↗Nucleicritical
PaloAlto Networks Expedition - Remote Code Execution
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RIESGO
abrir ↗Nucleihigh
Palo Alto Expedition - SQL Injection
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RIESGO
abrir ↗Nucleihigh
PAN-OS Management Web Interface - Command Injection
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir ↗Nucleihigh
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Remote Code Execution
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
61RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.