Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4201 exploits
Nucleimedium
Stop User Enumeration WordPress plugin - Authentication Bypass
Stop User Enumeration < 1.7.3 - Protection Bypass
28RIESGO
abrir ↗Nucleicritical
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RIESGO
abrir ↗Nucleicritical
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RIESGO
abrir ↗Nucleicritical
Ads Pro Plugin <= 4.89 - Local File Inclusion
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion
41RIESGO
abrir ↗Nucleimedium
Liferay Portal - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024
28RIESGO
abrir ↗Nucleihigh
Relevanssi <= 4.24.4 (Free) - Unauthenticated SQL Injection
Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection
56RIESGO
abrir ↗Nucleimedium
MapTiler Tileserver-php v2.0 - Unauthenticated XSS
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e
63RIESGO
abrir ↗Nucleihigh
MapTiler Tileserver-php v2.0 - Unauthenticated File Read
MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is resp
56RIESGO
abrir ↗Nucleimedium
MailEnable Mail Service < v10 - Cross-Site Scripting
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via
75RIESGO
abrir ↗Nucleihigh
White Star Software ProTop - Directory Traversal
A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically
56RIESGO
abrir ↗Nucleicritical
Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code Execution
Authentication Bypass
100RIESGO
abrir ↗Nucleihigh
WordPress Madara Theme < 2.2.2.1 - Local File Inclusion
Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion
63RIESGO
abrir ↗Nucleimedium
Liferay Portal & DXP - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025
28RIESGO
abrir ↗Nucleicritical
JEHC-BPM - Remote Code Execute
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
43RIESGO
abrir ↗Nucleicritical
Blink Router - Command Injection
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26
43RIESGO
abrir ↗Nucleicritical
Samsung MagicINFO 9 Server - File Upload & Remote Code Execution
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
98RIESGO
abrir ↗Nucleihigh
YesWiki Reflected XSS via File Upload
YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
36RIESGO
abrir ↗Nucleimedium
Broadstreet WordPress plugin - Reflected XSS
Broadstreet < 1.51.8 - Reflected XSS
28RIESGO
abrir ↗Nucleimedium
YesWiki <= 4.5.1 - Cross-Site Scripting
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
28RIESGO
abrir ↗Nucleimedium
YesWiki < 4.5.4 - Cross-Site Scripting
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
28RIESGO
abrir ↗Nucleihigh
XWiki REST API - Attachments Disclosure
XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API
28RIESGO
abrir ↗Nucleimedium
Vite Dev Server - Information Exposure
Vite's server.fs.deny bypassed with /. for files under project root
28RIESGO
abrir ↗Nucleihigh
Java-springboot-codebase 1.1 - Arbitrary File Read
Unauthenticated Arbitrary File Read via Absolute Path
56RIESGO
abrir ↗Nucleicritical
Mitel 6000 - OS Command Injection
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th
40RIESGO
abrir ↗Nucleimedium
Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting
An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the sour
28RIESGO
abrir ↗Nucleihigh
Personal Weather Station Dashboard 12 - Directory Traversal
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ direct
28RIESGO
abrir ↗Nucleihigh
WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download
WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
36RIESGO
abrir ↗Nucleimedium
L-Soft LISTSERV <16.5-2018a - Cross-Site Scripting
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
38RIESGO
abrir ↗Nucleihigh
Webmin < 1.920 - Authenticated Remote Code Execution
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise
50RIESGO
abrir ↗Nucleimedium
WordPress My Calendar <= 3.1.9 - Cross-Site Scripting
The my-calendar plugin before 3.1.10 for WordPress has XSS.
18RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.