Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleihigh
Strapi Versions <=4.5.5 - SSTI to Remote Code Execution
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RIESGO
abrir
Nucleimedium
Tiempo.com <= 0.1.2 - Cross-Site Scripting
Tiempo.com <= 0.1.2 - Reflected XSS
18RIESGO
abrir
Nucleihigh
Strapi Versions <=4.5.6 - Authentication Bypass
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login pro
36RIESGO
abrir
Nucleimedium
Securepoint UTM - Leaking Remote Memory Contents
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information dis
28RIESGO
abrir
Nucleihigh
SugarCRM Unauthenticated - Remote Code Execution
CVE-2023-22952HIGHbajo ataque
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because o
100RIESGO
abrir
Nucleihigh
Cellinx NVT Web Server - Local File Disclosure
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFi
38RIESGO
abrir
Nucleimedium
wpForo Forum <= 2.1.8 - Cross-Site Scripting
wpForo Forum < 2.1.9 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleimedium
Art Gallery Management System Project v1.0 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RIESGO
abrir
Nucleicritical
SolarView Compact 6.00 - OS Command Injection
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
Nucleicritical
WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir
Nucleicritical
WordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL Injection
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection
48RIESGO
abrir
Nucleimedium
Quick Event Manager < 9.7.5 - Cross-Site Scripting
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability
28RIESGO
abrir
Nucleicritical
Jms Blog - SQL Injection
PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
55RIESGO
abrir
Nucleihigh
Appwrite <=1.2.1 - Server-Side Request Forgery
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favic
48RIESGO
abrir
Nucleimedium
Request-Baskets <= 1.2.1 - Server Side Request Forgery
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
Nucleihigh
GDidees CMS v3.9.1 - Arbitrary File Download
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RIESGO
abrir
Nucleimedium
OpenCATS - Open Redirect
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET pa
28RIESGO
abrir
Nucleicritical
MStore API <= 3.9.2 - Authentication Bypass
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
Nucleicritical
MStore API <= 3.9.1 - Authentication Bypass
MStore API <= 3.9.1 - Authentication Bypass
43RIESGO
abrir
Nucleicritical
PaperCut - Unauthenticated Remote Code Execution
CVE-2023-27350CRITICALbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
Nucleihigh
PaperCut NG - Authentication Bypass
CVE-2023-27351HIGHbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
88RIESGO
abrir
Nucleicritical
SPIP - Remote Command Execution
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
Nucleimedium
WordPress Core <=6.2 - Directory Traversal
WordPress Core < 6.2.1 - Directory Traversal
70RIESGO
abrir
Nucleicritical
Home Assistant Supervisor - Authentication Bypass
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for
65RIESGO
abrir
Nucleicritical
Apache Superset - Authentication Bypass
CVE-2023-27524HIGHbajo ataque
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
Nucleicritical
Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret
Dragonfly2 vulnerable to hard coded cyptographic key
55RIESGO
abrir
Nucleimedium
ReadToMyShoe - Generation of Error Message Containing Sensitive Information
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing
36RIESGO
abrir
Nucleimedium
WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS
WordPress Redirect After Login Plugin <= 0.1.9 is vulnerable to Cross Site Scripting (XSS)
28RIESGO
abrir
Nucleicritical
PrestaShop `tshirtecommerce` Module - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
43RIESGO
abrir
Nucleihigh
tshirtecommerce PrestaShop Module - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
43RIESGO
abrir
anteriorpágina 102 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.