Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4201 exploits
Nucleicritical
Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dns
95RIESGO
abrir ↗Nucleimedium
Verint Workforce Optimization 15.2.8.10048 - Cross-Site Scripting
Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.
30RIESGO
abrir ↗Nucleimedium
Nova noVNC - Open Redirect
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to
23RIESGO
abrir ↗Nucleimedium
IceWarp Mail Server - Open Redirect
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the refere
18RIESGO
abrir ↗Nucleimedium
KodExplorer - Cross-Site Scripting
A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.
18RIESGO
abrir ↗Nucleihigh
PrestaHome Blog for PrestaShop <1.7.8 - SQL Injection
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestash
23RIESGO
abrir ↗Nucleimedium
Apache Druid - Local File Inclusion
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
60RIESGO
abrir ↗Nucleimedium
WordPress iQ Block Country <=1.2.11 - Cross-Site Scripting
WordPress iQ Block Country plugin <= 1.2.11 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
28RIESGO
abrir ↗Nucleicritical
WordPress Image Hover Ultimate - Unauthenticated Settings Update
WordPress Image Hover Effects Ultimate plugin <= 9.6.1 - Unauthenticated Arbitrary Options Update leading to full website compromise
43RIESGO
abrir ↗Nucleimedium
QSAN Storage Manager <3.3.3 - Cross-Site Scripting
QSAN Storage Manager - Reflected Cross-Site Scripting
28RIESGO
abrir ↗Nucleicritical
KevinLAB BEMS 1.0 - SQL Injection
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id
18RIESGO
abrir ↗Nucleihigh
KevinLAB BEMS (Building Energy Management System) - Backdoor Account
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocu
18RIESGO
abrir ↗Nucleihigh
Jeecg Boot <= 2.4.5 - Information Disclosure
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege an
36RIESGO
abrir ↗Nucleihigh
Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and vi
36RIESGO
abrir ↗Nucleicritical
Zoho ManageEngine ServiceDesk Plus - Authentication Bypass
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs w
95RIESGO
abrir ↗Nucleimedium
Zoho ManageEngine ADSelfService Plus <=6103 - Cross-Site Scripting
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
18RIESGO
abrir ↗Nucleicritical
PrestaShop SmartBlog <4.0.6 - SQL Injection
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthentica
40RIESGO
abrir ↗Nucleimedium
Tiny Java Web Server - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS
18RIESGO
abrir ↗Nucleicritical
Apache ShenYu Admin JWT - Authentication Bypass
Apache ShenYu Admin bypass JWT authentication
50RIESGO
abrir ↗Nucleihigh
Virtua Software Cobranca <12R - Blind SQL Injection
Virtua Cobranca before 12R allows SQL Injection on the login page.
43RIESGO
abrir ↗Nucleimedium
WP Cerber < 8.9.3 - Broken Access Control
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
18RIESGO
abrir ↗Nucleimedium
phpfastcache - phpinfo Resource Exposure
Exposed phpinfo() in PhpFastCache
28RIESGO
abrir ↗Nucleimedium
Hotel Druid 3.0.2 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid applic
18RIESGO
abrir ↗Nucleihigh
Wipro Holmes Orchestrator 20.4.1 - Arbitrary File Download
The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary
23RIESGO
abrir ↗Nucleihigh
Wipro Holmes Orchestrator 20.4.1 - Information Disclosure
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as report
30RIESGO
abrir ↗Nucleihigh
Canon Devices - Authentication Bypass in Catwalk Server
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server
18RIESGO
abrir ↗Nucleimedium
Nagios XI < 5.8.6 - Cross-Site Scripting
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a
40RIESGO
abrir ↗Nucleimedium
Gnuboard 5 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in gnuboard/gnuboard5
36RIESGO
abrir ↗Nucleimedium
WordPress Redux Framework <=4.2.11 - Information Disclosure
Gutenberg Template Library & Redux Framework <= 4.2.11 Sensitive Information Disclosure
33RIESGO
abrir ↗Nucleicritical
Apache Airflow - Unauthenticated Variable Import
Apache Airflow: Variable Import endpoint missed authentication check
40RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.