Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleihigh
mlflow - Path Traversal
Path Traversal: '\..\filename' in mlflow/mlflow
36RIESGO
abrir
Nucleicritical
WordPress POST SMTP Mailer <= 2.8.7 - Authorization Bypass
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir
Nucleicritical
Hikvision IP ping.php - Command Execution
Hikvision Intercom Broadcasting System ping.php os command injection
70RIESGO
abrir
Nucleihigh
Mlflow <2.9.2 - Path Traversal
Path Traversal: '\..\filename' in mlflow/mlflow
58RIESGO
abrir
Nucleicritical
Better Search Replace < 1.4.5 - PHP Object Injection
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
68RIESGO
abrir
Nucleimedium
WP Recipe Maker <= 9.1.0 - Reflected XSS via Referer Header
WP Recipe Maker <= 9.1.0 - Reflected Cross-Site Scripting via Referer
28RIESGO
abrir
Nucleihigh
Mlflow <2.8.0 - Local File Inclusion
Path Traversal: '\..\filename'
43RIESGO
abrir
Nucleicritical
Shield Security WP Plugin <= 18.5.9 - Local File Inclusion
Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion
55RIESGO
abrir
Nucleihigh
GitLab - Account Takeover via Password Reset
CVE-2023-7028CRITICALbajo ataque
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
Nucleimedium
WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection
WeiYe-Jing datax-web HTTP POST Request killJob os command injection
28RIESGO
abrir
Nucleihigh
WordPress BackWPup < 4.0.4 - Backup File Disclosure
BackWPup < 4.0.4 - Unauthenticated Backup Download
36RIESGO
abrir
Nucleihigh
JetBackup <= 2.0.9.7 - Sensitive Information Exposure via Directory Listing
JetBackup < 2.0.9.9 - Directory Listing Exposing Backups
36RIESGO
abrir
Nucleimedium
System Dashboard < 2.8.10 - Cross-Site Scripting
System Dashboard < 2.8.10 - XSS via Header Injection
28RIESGO
abrir
Nucleihigh
Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read
Ozeki SMS Gateway <= 10.3.208 Unauthenticated Arbitrary File Read
36RIESGO
abrir
Nucleicritical
JS Help Desk <= 2.8.2 - SQL Injection
JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie
36RIESGO
abrir
Nucleicritical
PAN-OS Management Web Interface - Authentication Bypass
CVE-2024-0012CRITICALbajo ataqueransomware
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
Nucleicritical
SpiderFlow Crawler Platform - Remote Code Execution
spider-flow FunctionController.java FunctionService.saveFunction code injection
33RIESGO
abrir
Nucleicritical
Github Enterprise Authenticated Remote Code Execution
Unsafe Reflection in Github Enterprise Server leading to Command Injection
58RIESGO
abrir
Nucleicritical
Fortra GoAnywhere MFT - Authentication Bypass
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir
Nucleimedium
EventON (Free < 2.2.8, Premium < 4.5.5) - Information Disclosure
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RIESGO
abrir
Nucleimedium
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
28RIESGO
abrir
Nucleihigh
Ncast busiFacade - Remote Command Execution
Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure
60RIESGO
abrir
Nucleihigh
Download Manager < 3.3.04 - Unauthenticated Arbitrary Shortcode Execution
Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution
36RIESGO
abrir
Nucleimedium
Gradio - Server Side Request Forgery
SSRF Vulnerability in gradio-app/gradio
28RIESGO
abrir
Nucleimedium
LearnPress < 4.2.7.4 - Course Material - Information Disclosure
LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API
28RIESGO
abrir
Nucleihigh
Give WP Plugin < 3.19.0 - Cross-Site Scripting
Give < 3.19.0 - Reflected XSS
28RIESGO
abrir
Nucleicritical
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir
Nucleimedium
W3 Total Cache < 2.8.2 - Log File Exposure
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
28RIESGO
abrir
Nucleihigh
WordPress Collapsing Categories <= 3.0.8 - SQL Injection
Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection
56RIESGO
abrir
Nucleimedium
LearnDash LMS < 4.10.3 - Sensitive Information Exposure
LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API
28RIESGO
abrir
anteriorpágina 137 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.