Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleihigh
GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.
Path traversal in GLPI barcode plugin
75RIESGO
abrir
Nucleihigh
Grafana v8.x - Arbitrary File Read
CVE-2021-43798HIGHbajo ataque
Grafana path traversal
100RIESGO
abrir
Nucleicritical
Pinterest Automatic < 4.14.4 - Unauthenticated Arbitrary Options Update
Pinterest Automatic <= 4.14.3 - Unuathenticated Arbitrary Options Update
43RIESGO
abrir
Nucleimedium
Admidio - Cross-Site Scripting
Cross-site Scripting (XSS) when redirect an url
36RIESGO
abrir
Nucleihigh
Gradio < 2.5.0 - Arbitrary File Read
Files on the host computer can be accessed from the Gradio interface
36RIESGO
abrir
Nucleicritical
Zoho ManageEngine ServiceDesk Plus - Remote Code Execution
CVE-2021-44077CRITICALbajo ataque
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RIESGO
abrir
Nucleihigh
Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remo
23RIESGO
abrir
Nucleihigh
Alibaba Sentinel - Server-side request forgery (SSRF)
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
18RIESGO
abrir
Nucleicritical
Reprise License Manager 14.2 - Authentication Bypass
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a
30RIESGO
abrir
Nucleihigh
D-Link DAP-1620 - Local File Inclusion
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RIESGO
abrir
Nucleimedium
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RIESGO
abrir
Nucleihigh
Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RIESGO
abrir
Nucleihigh
Telesquare TLR-2855KS6 - Arbitrary File Creation
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
43RIESGO
abrir
Nucleicritical
Telesquare TLR-2855KS6 - Arbitrary File Deletion
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil
60RIESGO
abrir
Nucleicritical
SDT-CW3B1 1.1.0 - OS Command Injection
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RIESGO
abrir
Nucleicritical
Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de
50RIESGO
abrir
Nucleicritical
GenieACS => 1.2.8 - OS Command Injection
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping
23RIESGO
abrir
Nucleimedium
Keystone 6 Login Page - Open Redirect and Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in keystonejs/keystone
36RIESGO
abrir
Nucleimedium
WordPress Visual Form Builder <3.0.8 - Information Disclosure
Visual Form Builder < 3.0.6 - Unauthenticated Information Disclosure
18RIESGO
abrir
Nucleimedium
WordPress Cookie Information/Free GDPR Consent Solution <2.0.8 - Cross-Site Scripting
Cookie Information < 2.0.8 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleimedium
WordPress All-in-one Floating Contact Form <2.0.4 - Cross-Site Scripting
All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)
18RIESGO
abrir
Nucleimedium
WooCommerce Stored Exporter WordPress Plugin < 2.7.1 - Cross-Site Scripting
WooCommerce – Store Exporter < 2.7.1 - Reflected Cross-Site Scripting (XSS)
18RIESGO
abrir
Nucleimedium
WordPress Accessibility Helper <0.6.0.7 - Cross-Site Scripting
WP Accessibility Helper (WAH) < 0.6.0.7 - Reflected Cross-Site Scripting (XSS)
18RIESGO
abrir
Nucleimedium
WordPress Page Builder KingComposer <=2.9.6 - Open Redirect
Page Builder KingComposer <= 2.9.6 - Open Redirect
18RIESGO
abrir
Nucleicritical
Photo Gallery by 10Web < 1.6.0 - SQL Injection
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
60RIESGO
abrir
Nucleimedium
CMP WordPress < 4.0.19 - Broken Access Control
Coming Soon & Maintenance Plugin by NiteoThemes < 4.0.19 - Unauthenticated Arbitrary CSS Update
18RIESGO
abrir
Nucleimedium
WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scripting
WP RSS Aggregator < 4.20 - Reflected Cross-Site Scripting (XSS)
18RIESGO
abrir
Nucleimedium
WordPress Permalink Manager <2.2.15 - Cross-Site Scripting
Permalink Manager < 2.2.15 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleimedium
WordPress NewStatPress <1.3.6 - Cross-Site Scripting
NewStatPress < 1.3.6 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleimedium
WordPress Plugin MapPress <2.73.4 - Cross-Site Scripting
MapPress Maps for WordPress < 2.73.4 - Reflected Cross-Site scripting
18RIESGO
abrir
anteriorpágina 104 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.