Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
4201 exploits
Nucleihigh
ZimaOS <= v1.2.4 - Sensitive Information Disclosure
ZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data Leak
41RIESGO
abrir ↗Nucleicritical
Plenti < v0.7.2 - OS Command Injection
Plenti arbitrary file write vulnerability
36RIESGO
abrir ↗Nucleihigh
Sonatype Nexus Repository Manager 3 - Local File Inclusion
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗Nucleihigh
Zitadel - User Registration Bypass
Zitadel User Registration Bypass Vulnerability
36RIESGO
abrir ↗Nucleimedium
Scoold < 1.64.0 - Authentication Bypass
Semicolon Path Injection on API /api;/config
36RIESGO
abrir ↗Nucleihigh
Symfony Profiler - Remote Access via Injected Arguments
Ability to change environment from query in symfony/runtime
48RIESGO
abrir ↗Nucleicritical
WordPress Stacks Mobile App Builder <=5.2.3 - Authentication Bypass
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RIESGO
abrir ↗Nucleicritical
WP Query Console <= 1.0 - Remote Code Execution
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir ↗Nucleicritical
WordPress Easy Digital Downloads <= 3.2.12 - SQL Injection
WordPress Easy Digital Downloads plugin <= 3.2.12 - SQL Injection vulnerability
43RIESGO
abrir ↗Nucleicritical
Aviatrix Controller - Remote Code Execution
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RIESGO
abrir ↗Nucleihigh
Cleo Harmony < 5.8.0.21 - Arbitary File Read
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RIESGO
abrir ↗Nucleihigh
Nexus Repository 2 - Remote Code Execution
Nexus Repository 2 - Remote Code Execution
56RIESGO
abrir ↗Nucleicritical
Hash Form <= 1.1.0 - Arbitrary File Upload
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RIESGO
abrir ↗Nucleimedium
GestioIP - Reflected Cross-Site Scripting
The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and en
48RIESGO
abrir ↗Nucleihigh
DATAGERRY - Improper Access Control
The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability.
48RIESGO
abrir ↗Nucleicritical
openSIS Classic v9.1 - SQL Injection
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The
63RIESGO
abrir ↗Nucleimedium
TOTOLINK CX-A3002RU - Remote Code Execution
An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300R
28RIESGO
abrir ↗Nucleicritical
CyberPanel - Command Injection
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir ↗Nucleicritical
ZoneMinder v1.37.* <= 1.37.64 - SQL Injection
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RIESGO
abrir ↗Nucleimedium
Changedetection.io <= 0.47.4 - Path Traversal
changedetection.io Path Traversal vulnerability
28RIESGO
abrir ↗Nucleicritical
CyberPanel v2.3.6 Pre-Auth Remote Code Execution
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir ↗Nucleicritical
CyberPanel - Command Injection
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RIESGO
abrir ↗Nucleimedium
iTop - User Enumeration via REST Endpoint
Users enumeration allowed through Rest API in Combodo iTop
36RIESGO
abrir ↗Nucleimedium
Brother MFC-L9570CDW - Information Disclosure
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RIESGO
abrir ↗Nucleicritical
Brother Printers – Authentication Bypass via Default Admin Password
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RIESGO
abrir ↗Nucleicritical
ServiceNow - Incomplete Input Validation
Incomplete Input Validation in GlideExpression Script
100RIESGO
abrir ↗Nucleimedium
FleetCart 4.1.1 - Information Disclosure
EnvaySoft FleetCart information disclosure
33RIESGO
abrir ↗Nucleicritical
My Geo Posts Free <= 1.2 - PHP Object Injection
WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
63RIESGO
abrir ↗Nucleihigh
WpStickyBar <= 2.1.0 - SQL Injection
WpStickyBar <= 2.1.0 - Unauthenticated SQLi
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.