Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4193 exploits
Nucleicritical
Grafana Post-Auth DuckDB - SQL Injection To File Read
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir ↗Nucleihigh
Polyaxon - Unauthenticated Directory Traversal
Directory Traversal in polyaxon/polyaxon
36RIESGO
abrir ↗Nucleicritical
PaloAlto Networks Expedition - Remote Code Execution
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RIESGO
abrir ↗Nucleihigh
Palo Alto Expedition - SQL Injection
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RIESGO
abrir ↗Nucleihigh
PAN-OS Management Web Interface - Command Injection
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir ↗Nucleihigh
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Remote Code Execution
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
61RIESGO
abrir ↗Nucleicritical
Four-Faith F3x36 - Authentication Bypass
Four-Faith F3x36 Hidden Debug Credentials
43RIESGO
abrir ↗Nucleicritical
Hunk Companion <= 1.8.4 - Arbitrary Plugin Installation
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RIESGO
abrir ↗Nucleimedium
EKC Tournament Manager WordPress plugin - Path Traversal
EKC Tournament Manager < 2.2.2 - Local File Download Vulnerability
28RIESGO
abrir ↗Nucleihigh
WordPress UIX Shortcodes <= 1.9.7 - Unauthenticated Shortcode Execution
Uix Shortcodes – Compatible with Gutenberg <= 1.9.9 - Unauthenticated Arbitrary Shortcode Execution
36RIESGO
abrir ↗Nucleicritical
WordPress WP-Advanced-Search <= 3.3.9 - SQL Injection
WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection
28RIESGO
abrir ↗Nucleihigh
HuangDou UTCMS V9 - OS Command Injection
HuangDou UTCMS cli.php os command injection
50RIESGO
abrir ↗Nucleihigh
PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download
PDF Generator Addon for Elementor Page Builder <= 2.0.0 - Unauthenticated Arbitrary File Download
36RIESGO
abrir ↗Nucleicritical
Crypto <= 2.15 - Authentication Bypass
Crypto <= 2.18 - Authentication Bypass via log_in
43RIESGO
abrir ↗Nucleicritical
Palo Alto Networks Expedition - OS Command Injection
Expedition: OS Command Injection Vulnerability
58RIESGO
abrir ↗Nucleicritical
PAN-OS Management Interface - Path Confusion to Authentication Bypass
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir ↗Nucleimedium
PAN-OS - Reflected Cross-Site Scripting
PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal
35RIESGO
abrir ↗Nucleicritical
Ivanti Connect Secure - Stack-based Buffer Overflow
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir ↗Nucleicritical
Elber ESE DVB-S/S2 - Authentication Bypass
Elber Communications Equipment Authentication Bypass Using an Alternate Path or Channel
43RIESGO
abrir ↗Nucleicritical
DocsGPT - Unauthenticated Remote Code Execution
Remote Code Execution in DocsGPT
68RIESGO
abrir ↗Nucleicritical
GoAnywhere - Authentication Bypass
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RIESGO
abrir ↗Nucleihigh
WordPress OrderConvo < 14 - Path Traversal
OrderConvo < 14 - Unauthenticated Arbitrary File Read
56RIESGO
abrir ↗Nucleihigh
AC Smart II - Authentication Bypass
Unauth Admin Reset Password on AC Smart II
36RIESGO
abrir ↗Nucleimedium
ChanCMS <= 3.3.0 - SQL Injection
yanyutao0402 ChanCMS Api.js search sql injection
28RIESGO
abrir ↗Nucleimedium
ChanCMS <= 3.3.0 - Server-Side Request Forgery
yanyutao0402 ChanCMS getArticle CollectController server-side request forgery
28RIESGO
abrir ↗Nucleicritical
ChurchCRM - SQL Injection
SQL Injection in ChurchCRM newCountName Parameter via EditEventTypes.php
43RIESGO
abrir ↗Nucleihigh
Cockpit < 2.4.1 - Arbitrary File Upload
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can us
41RIESGO
abrir ↗Nucleimedium
KLog Server - Path Traversal
Path Traversal in Komtera Technolgies' KLog Server
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.