Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleicritical
vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP reques
68RIESGO
abrir
Nucleicritical
GeoServer OGC Filter - SQL Injection
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir
Nucleimedium
WordPress Easy Forms for Mailchimp Plugin < 6.8.9 - Cross-Site Scripting
Easy Forms for Mailchimp < 6.8.9 - Reflected XSS
28RIESGO
abrir
Nucleihigh
Apache Druid Kafka Connect - Remote Code Execution
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RIESGO
abrir
Nucleicritical
D-Link DIR820LA1_FW105B03 'ping_addr' - OS Command Injection
CVE-2023-25280CRITICALbajo ataque
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a cr
95RIESGO
abrir
Nucleimedium
ChurchCRM 4.5.3 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web
28RIESGO
abrir
Nucleihigh
Metersphere - Arbitrary File Read
Improper access control to download file in metersphere
48RIESGO
abrir
Nucleicritical
Ruckus Wireless Admin - Remote Code Execution
CVE-2023-25717CRITICALbajo ataque
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated
95RIESGO
abrir
Nucleicritical
ZoneMinder Snapshots - Command Injection
ZoneMinder vulnerable to Missing Authorization
58RIESGO
abrir
Nucleihigh
Lexmark Printers - Command Injection
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
68RIESGO
abrir
Nucleimedium
KiviCare WordPress Plugin - Cross-Site Scripting
KiviCare Management System < 3.2.1 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleihigh
STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2
68RIESGO
abrir
Nucleihigh
STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2
61RIESGO
abrir
Nucleicritical
Arcserve UDP <= 9.0.6034 - Authentication Bypass
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe
50RIESGO
abrir
Nucleihigh
Adobe Coldfusion - Authentication Bypass
CVE-2023-38205 issues | ColdFusion Admin Panel Access
41RIESGO
abrir
Nucleihigh
Adobe ColdFusion - Local File Read
CVE-2023-26360HIGHbajo ataque
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
Nucleicritical
Jorani 1.0.0 - Remote Code Execution
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
60RIESGO
abrir
Nucleicritical
Weaver E-Office 9.5 - Remote Code Execution
Weaver E-Office uploadify.php unrestricted upload
33RIESGO
abrir
Nucleicritical
DCBI-Netlog-LAB v1.0 - Command Injection
An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attac
55RIESGO
abrir
Nucleimedium
ChurchCRM 4.5.3 - Cross-Site Scripting
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr
28RIESGO
abrir
Nucleimedium
ChurchCRM 4.5.3 - Cross-Site Scripting
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr
28RIESGO
abrir
Nucleimedium
ATutor < 2.2.1 - Cross Site Scripting
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows r
28RIESGO
abrir
Nucleicritical
PrestaShop AdvancedPopupCreator - SQL Injection
Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the compo
43RIESGO
abrir
Nucleicritical
Jms Blog - SQL Injection
PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
55RIESGO
abrir
Nucleihigh
Appwrite <=1.2.1 - Server-Side Request Forgery
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favic
48RIESGO
abrir
Nucleimedium
Request-Baskets <= 1.2.1 - Server Side Request Forgery
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
Nucleihigh
GDidees CMS v3.9.1 - Arbitrary File Download
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RIESGO
abrir
Nucleimedium
OpenCATS - Open Redirect
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET pa
28RIESGO
abrir
Nucleicritical
MStore API <= 3.9.2 - Authentication Bypass
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
Nucleicritical
MStore API <= 3.9.1 - Authentication Bypass
MStore API <= 3.9.1 - Authentication Bypass
43RIESGO
abrir
anteriorpágina 121 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.