Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.460 exploits
Exploit-DB
ThingsBoard 3.3.1 'description' - Stored Cross-Site Scripting (XSS)
CVE-2021-42751webappsmultiple09 ago 2022
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat
23RIESGO
abrir
Exploit-DB
Feehi CMS 2.1.1 - Stored Cross-Site Scripting (XSS)
CVE-2022-34140webappsphp09 ago 2022
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to
23RIESGO
abrir
Exploit-DB
Prestashop blockwishlist module 2.1.0 - SQLi
CVE-2022-31101HIGHwebappsphp09 ago 2022
SQL Injection in prestashop/blockwishlist
61RIESGO
abrir
Exploit-DB
uftpd 2.10 - Directory Traversal (Authenticated)
CVE-2020-20277remotelinux02 ago 2022
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver
28RIESGO
abrir
Exploit-DB
Wavlink WN533A8 - Cross-Site Scripting (XSS)
CVE-2022-34048webappshardware01 ago 2022
Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via th
38RIESGO
abrir
Exploit-DB
Wavlink WN533A8 - Password Disclosure
CVE-2022-34046webappshardware01 ago 2022
An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via vie
43RIESGO
abrir
Exploit-DB
WordPress Plugin Duplicator 1.4.6 - Unauthenticated Backup Download
CVE-2022-2551webappsphp01 ago 2022
Duplicator < 1.4.7 - Unauthenticated Backup Download
43RIESGO
abrir
Exploit-DB
Easy Chat Server 3.1 - Remote Stack Buffer Overflow (SEH)
CVE-2004-2466remotewindows01 ago 2022
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username
60RIESGO
abrir
Exploit-DB
Wavlink WN530HG4 - Password Disclosure
CVE-2022-34047webappshardware01 ago 2022
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via v
43RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Duplicator 1.4.7 - Information Disclosure
CVE-2022-2552webappsphp01 ago 2022
Duplicator < 1.4.7.1 - Unauthenticated System Information Disclosure
43RIESGO
abrir
Exploit-DB
Dingtian-DT-R002 3.1.276A - Authentication Bypass
CVE-2022-29593MEDIUMwebappshardware29 jul 2022
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RIESGO
abrir
Exploit-DB
rpc.py 0.6.0 - Remote Code Execution (RCE)
CVE-2022-35411remotepython29 jul 2022
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RIESGO
abrir
Exploit-DB
Magnolia CMS 6.2.19 - Stored Cross-Site Scripting (XSS)
CVE-2022-33098webappsphp21 jul 2022
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.
35RIESGO
abrir
Exploit-DB
CodoForum v5.1 - Remote Code Execution (RCE)
CVE-2022-31854webappsphp21 jul 2022
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin
50RIESGO
abrir
Exploit-DB
IOTransfer 4.0 - Remote Code Execution (RCE)
CVE-2022-24562remotewindows21 jul 2022
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary
35RIESGO
abrir
Exploit-DB
OctoBot WebInterface 0.4.3 - Remote Code Execution (RCE)
CVE-2021-36711webappsmultiple21 jul 2022
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
28RIESGO
abrir
Exploit-DB
Nginx 1.20.0 - Denial of Service (DOS)
CVE-2021-23017remotemultiple11 jul 2022
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir
Exploit-DB
WSO2 Management Console (Multiple Products) - Unauthenticated Reflected Cross-Site Scripting (XSS)
CVE-2022-29548MEDIUMwebappsphp27 jun 2022
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,
60RIESGO
abrir
Exploit-DB
ChurchCRM 4.4.5 - SQLi
CVE-2022-31325webappsphp14 jun 2022
There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.
23RIESGO
abrir
Exploit-DB
Virtua Software Cobranca 12S - SQLi
CVE-2021-37589remotewindows14 jun 2022
Virtua Cobranca before 12R allows SQL Injection on the login page.
50RIESGO
abrir
Exploit-DB
SolarView Compact 6.00 - 'pow' Cross-Site Scripting (XSS)
CVE-2022-29301webappshardware14 jun 2022
20RIESGO
abrir
Exploit-DB
SolarView Compact 6.00 - 'time_begin' Cross-Site Scripting (XSS)
CVE-2022-29299webappshardware14 jun 2022
20RIESGO
abrir
Exploit-DB
Marval MSM v14.19.0.12476 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-31885remotewindows14 jun 2022
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
35RIESGO
abrir
Exploit-DB
Avantune Genialcloud ProJ 10 - Cross-Site Scripting (XSS)
CVE-2022-29296webappsmultiple14 jun 2022
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attack
23RIESGO
abrir
Exploit-DB
Sourcegraph Gitserver 3.36.3 - Remote Code Execution (RCE)
CVE-2022-23642HIGHremotemultiple14 jun 2022
Code Injection in Sourcegraph
78RIESGO
abrir
Exploit-DB
Pandora FMS v7.0NG.742 - Remote Code Execution (RCE) (Authenticated)
CVE-2020-5844webappsphp14 jun 2022
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t
35RIESGO
abrir
Exploit-DB
Marval MSM v14.19.0.12476 - Cross-Site Request Forgery (CSRF)
CVE-2022-31886remotewindows14 jun 2022
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending
23RIESGO
abrir
Exploit-DB
Confluence Data Center 7.18.0 - Remote Code Execution (RCE)
CVE-2022-26134CRITICALbajo ataqueransomwarewebappsjava10 jun 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
Exploit-DB
Telesquare SDT-CW3B1 1.1.0 - OS Command Injection
CVE-2021-46422remotehardware03 jun 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RIESGO
abrir
Exploit-DB
Zyxel USG FLEX 5.21 - OS Command Injection
CVE-2022-30525CRITICALbajo ataqueremotehardware03 jun 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.