Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
CVE-2021-42013CRITICALbajo ataqueransomwarewebappsmultiple25 oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Exploit-DB
Hikvision Web Server Build 210702 - Command Injection
CVE-2021-36260CRITICALbajo ataquewebappshardware25 oct 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
Exploit-DB
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24444webappsphp25 oct 2021
TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
23RIESGO
abrir
Exploit-DB
Jetty 9.4.37.v20210219 - Information Disclosure
CVE-2021-28164MEDIUMwebappsjava22 oct 2021
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RIESGO
abrir
Exploit-DB
SonicWall SMA 10.2.1.0-17sv - Password Reset
CVE-2021-20034webappshardware20 oct 2021
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal
45RIESGO
abrir
Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
CVE-2021-42566webappsmultiple19 oct 2021
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
38RIESGO
abrir
Exploit-DB
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24719webappsphp19 oct 2021
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RIESGO
abrir
Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
CVE-2021-42565webappsmultiple19 oct 2021
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
38RIESGO
abrir
Exploit-DB
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
CVE-2020-11738HIGHbajo ataquewebappsphp18 oct 2021
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RIESGO
abrir
Exploit-DB
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
CVE-2021-41382webappsmultiple18 oct 2021
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RIESGO
abrir
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
CVE-2018-16061webappshardware18 oct 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RIESGO
abrir
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
CVE-2018-16060webappshardware18 oct 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listi
28RIESGO
abrir
Exploit-DB
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
CVE-2021-41878webappsphp15 oct 2021
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RIESGO
abrir
Exploit-DB
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
CVE-2020-10770webappsjava13 oct 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RIESGO
abrir
Exploit-DB
Sonicwall SonicOS 7.0 - Host Header Injection
CVE-2021-20031webappshardware13 oct 2021
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management
43RIESGO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
CVE-2021-42013CRITICALbajo ataqueransomwarewebappsmultiple13 oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Exploit-DB
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2021-32172webappsphp08 oct 2021
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RIESGO
abrir
Exploit-DB
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
CVE-2021-42053webappspython08 oct 2021
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
23RIESGO
abrir
Exploit-DBVexDay Proof
Google SLO-Generator 2.0.0 - Code Execution
CVE-2021-22557MEDIUMlocallinux07 oct 2021
Code execution in SLO Generator via YAML Payload
33RIESGO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
CVE-2021-41773HIGHbajo ataqueransomwarewebappsmultiple06 oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
Exploit-DB
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
CVE-2021-26086MEDIUMbajo ataquewebappsmultiple06 oct 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RIESGO
abrir
Exploit-DB
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
CVE-2021-26085MEDIUMbajo ataqueransomwarewebappsjava05 oct 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RIESGO
abrir
Exploit-DB
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
CVE-2021-41318webappsmultiple01 oct 2021
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RIESGO
abrir
Exploit-DB
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24287webappsphp29 sep 2021
Select All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)
43RIESGO
abrir
Exploit-DB
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
CVE-2021-24286webappsphp29 sep 2021
Redirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
43RIESGO
abrir
Exploit-DB
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24275webappsphp28 sep 2021
Popup by Supsystic < 1.10.5 - Reflected Cross-Site scripting (XSS)
43RIESGO
abrir
Exploit-DB
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24274webappsphp28 sep 2021
Ultimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site scripting (XSS)
43RIESGO
abrir
Exploit-DB
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24610webappsphp28 sep 2021
TranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
23RIESGO
abrir
Exploit-DB
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24276webappsphp28 sep 2021
Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
43RIESGO
abrir
Exploit-DB
XAMPP 7.4.3 - Local Privilege Escalation
CVE-2020-11107localwindows27 sep 2021
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.