Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
4193 exploits
Nucleicritical
Securden Unified PAM - Authentication Bypass
Securden Unified PAM Authentication Bypass
48RIESGO
abrir
Nucleimedium
Parse Server - GraphQL Schema Information Disclosure
Parse Server exposes the data schema via GraphQL API
28RIESGO
abrir
Nucleimedium
WSO2 - Server Side Request Forgery
SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products
28RIESGO
abrir
Nucleimedium
Pi-hole Reflected XSS in 404-Error Page
Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error page
28RIESGO
abrir
Nucleihigh
ZTE ZXHN-F660T/F660A - Default Credentials
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge o
56RIESGO
abrir
Nucleihigh
Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token Exposure
docusaurus-plugin-content-gists Exposes GitHub Personal Access Token
43RIESGO
abrir
Nucleicritical
Microsoft SharePoint Server - Remote Code Execution (ToolShell)
CVE-2025-53770CRITICALbajo ataqueransomware
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
Nucleimedium
Microsoft SharePoint Server - Authentication Bypass (ToolShell)
Microsoft SharePoint Server Spoofing Vulnerability
50RIESGO
abrir
Nucleicritical
LaRecipe < 2.8.1 Remote Code Execution via SSTI
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RIESGO
abrir
Nucleicritical
Unauthenticated Arbitrary Plugin Upload in Alone Theme
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RIESGO
abrir
Nucleicritical
Laravel Livewire v3 - Remote Command Execution
CVE-2025-54068CRITICALbajo ataque
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir
Nucleicritical
Hoverfly <= 1.11.3 - Remote Code Execution
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
Nucleihigh
XWiki XML View - Sensitive Information Exposure
XWiki Platform: Password and email exposure in xml.vm fields
36RIESGO
abrir
Nucleicritical
Adobe Commerce - Authentication Bypass
CVE-2025-54236CRITICALbajo ataque
Adobe Commerce | Improper Input Validation (CWE-20)
100RIESGO
abrir
Nucleimedium
Adobe Experience Manager ≤ 6.5.23.0 – SSRF
Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)
28RIESGO
abrir
Nucleimedium
Adobe Experience Manager ≤ 6.5.23.0 - XML Injection
Adobe Experience Manager | XML Injection (aka Blind XPath Injection) (CWE-91)
28RIESGO
abrir
Nucleimedium
Copyparty <=1.18.6 - Cross-Site Scripting
copyparty Reflected XSS via Filter Parameter
48RIESGO
abrir
Nucleimedium
Heimdall Application Dashboard < 2.7.3 - Reflected XSS
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
36RIESGO
abrir
Nucleihigh
WordPress JS Archive List <= 6.1.5 - SQL Injection
WordPress JS Archive List Plugin < 6.1.6 - SQL Injection Vulnerability
63RIESGO
abrir
Nucleicritical
NestJS DevTools Integration - Remote Code Execution
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RIESGO
abrir
Nucleimedium
Astro SSR - Open Redirect
Astro: Duplicate trailing slash feature can lead to Open Redirects
28RIESGO
abrir
Nucleihigh
Stirling-PDF < 1.1.0 - Server-Side Request Forgery
Stirling-PDF SSRF vulnerability on /api/v1/convert/html/pdf
36RIESGO
abrir
Nucleihigh
Stirling-PDF SSRF via Markdown
Stirling-PDF SSRF vulnerability on /api/v1/convert/markdown/pdf
36RIESGO
abrir
Nucleicritical
WeGIA - Directory Traversal
WeGIA Path Traversal at endpoint 'html/socio/sistema/download_remessa.php' via parameter 'file'
43RIESGO
abrir
Nucleicritical
React Server Components - Remote Code Execution
CVE-2025-55182CRITICALbajo ataqueransomware
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Nucleihigh
React Server Components - Denial of Service
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1
68RIESGO
abrir
Nucleimedium
DokuWiki <= 2025-05-14a Librarian - Reflected Cross-Site Scripting
Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra
28RIESGO
abrir
Nucleihigh
Traccar(Windows) 6.1- 6.8.1 - Local File Inclusion
Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File
36RIESGO
abrir
Nucleimedium
WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)
WordPress Qwizcards <= 3.9.4 - Reflected XSS
28RIESGO
abrir
Nucleicritical
Oracle Identity Manager REST WebServices - Authentication Bypass
CVE-2025-61757CRITICALbajo ataque
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.