Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleihigh
Apache Druid - Remote Code Execution
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir
Nucleihigh
Hue Magic 3.0.0 - Local File Inclusion
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in fil
18RIESGO
abrir
Nucleihigh
Void Aural Rec Monitor 9.0.0.1 - SQL Injection
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a craft
23RIESGO
abrir
Nucleimedium
Atlassian Confluence < 5.8.6 - Server-Side Request Forgery
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers
30RIESGO
abrir
Nucleicritical
Confluence Server - Remote Code Execution
CVE-2021-26084CRITICALbajo ataqueransomware
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
Nucleimedium
Atlassian Confluence Server - Local File Inclusion
CVE-2021-26085MEDIUMbajo ataqueransomware
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RIESGO
abrir
Nucleimedium
Atlassian Jira Limited - Local File Inclusion
CVE-2021-26086MEDIUMbajo ataque
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RIESGO
abrir
Nucleimedium
Cacti - Cross-Site Scripting
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" t
18RIESGO
abrir
Nucleihigh
AfterLogic Aurora and WebMail Pro < 7.7.9 - Information Disclosure
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal
23RIESGO
abrir
Nucleicritical
Apache OFBiz <17.12.06 - Arbitrary Code Execution
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RIESGO
abrir
Nucleimedium
EPrints 3.4.2 - Cross-Site Scripting
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
18RIESGO
abrir
Nucleimedium
ImpressCMS <1.4.3 - Incorrect Authorization
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated atta
23RIESGO
abrir
Nucleihigh
ImpressCMS < 1.4.3 - SQL Injection
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
43RIESGO
abrir
Nucleimedium
EPrints 3.4.2 - Cross-Site Scripting
EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
18RIESGO
abrir
Nucleimedium
Redwood Report2Web 4.3.4.5 & 4.5.3 - Cross-Site Scripting
A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to
18RIESGO
abrir
Nucleimedium
Jenzabar 9.2x-9.2.2 - Cross-Site Scripting
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
23RIESGO
abrir
Nucleicritical
Apache OFBiz < 17.12.07 - Arbitrary Code Execution
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
30RIESGO
abrir
Nucleicritical
HPE Edgeline Infrastructure Manager <1.22 - Authentication Bypass
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infr
30RIESGO
abrir
Nucleicritical
Nacos <1.4.1 - Authentication Bypass
Authentication bypass
78RIESGO
abrir
Nucleihigh
Nacos <1.4.1 - Authentication Bypass
Authentication bypass
68RIESGO
abrir
Nucleimedium
Ghost CMS <=4.32 - Cross-Site Scripting
DOM XSS in Theme Preview
28RIESGO
abrir
Nucleimedium
Jellyfin 10.7.2 - Server Side Request Forgery
Unauthenticated GET requests through Remote Image endpoints
40RIESGO
abrir
Nucleihigh
XStream <1.4.17 - Remote Code Execution
XStream is vulnerable to a Remote Command Execution attack
58RIESGO
abrir
Nucleimedium
Prometheus - Open Redirect
Arbitrary redirects under /new endpoint
33RIESGO
abrir
Nucleimedium
Adminer <=4.8.0 - Cross-Site Scripting
XSS in doc_link
36RIESGO
abrir
Nucleimedium
Seo Panel 4.8.0 - Cross-Site Scripting
Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.
18RIESGO
abrir
Nucleimedium
SysAid Technologies 20.3.64 b14 - Cross-Site Scripting
SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.
18RIESGO
abrir
Nucleicritical
Laminas Project laminas-http - Remote Code Execution
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead
60RIESGO
abrir
Nucleicritical
Kaseya VSA < 9.5.7 - Credential Disclosure via Windows Agent
CVE-2021-30116CRITICALbajo ataqueransomware
Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
95RIESGO
abrir
Nucleicritical
Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code Execution
Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5
55RIESGO
abrir
anteriorpágina 107 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.