Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
Subrion CMS 4.2.1 - Arbitrary File Upload
CVE-2018-19422webappsphp17 may 2021
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir
Exploit-DB
IPFire 2.25 - Remote Code Execution (Authenticated)
CVE-2021-33393webappscgi17 may 2021
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It
50RIESGO
abrir
Exploit-DBVexDay Proof
Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated)
CVE-2021-31933HIGHwebappsphp14 may 2021
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a paramete
46RIESGO
abrir
Exploit-DB
ZeroShell 3.9.0 - Remote Command Execution
CVE-2019-12725webappslinux13 may 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
Exploit-DB
Firefox 72 IonMonkey - JIT Type Confusion
CVE-2019-17026HIGHbajo ataquelocalwindows_x86-6413 may 2021
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 and WPAD service 'Jscript.dll' - Use-After-Free
CVE-2020-0674HIGHbajo ataquelocalwindows_x86-6413 may 2021
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Exploit-DB
Microweber CMS 1.1.20 - Remote Code Execution (Authenticated)
CVE-2020-28337webappsphp10 may 2021
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to g
28RIESGO
abrir
Exploit-DB
b2evolution 7-2-2 - 'cf_name' SQL Injection
CVE-2021-28242webappsphp06 may 2021
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RIESGO
abrir
Exploit-DB
Piwigo 11.3.0 - 'language' SQL
CVE-2021-27973webappsphp03 may 2021
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
28RIESGO
abrir
Exploit-DB
GNU Wget < 1.18 - Arbitrary File Upload (2)
CVE-2016-4971remotelinux30 abr 2021
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RIESGO
abrir
Exploit-DB
Moodle 3.6.1 - Persistent Cross-Site Scripting (XSS)
CVE-2019-3810MEDIUMwebappsphp30 abr 2021
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported vers
38RIESGO
abrir
Exploit-DB
Cacti 1.2.12 - 'filter' SQL Injection
CVE-2020-14295webappsphp29 abr 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir
Exploit-DB
Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS)
CVE-2021-29460HIGHwebappsphp28 abr 2021
Cross-site scripting (XSS) from unsanitized uploaded SVG files
41RIESGO
abrir
Exploit-DB
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2)
CVE-2021-28419webappsphp26 abr 2021
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads
28RIESGO
abrir
Exploit-DB
DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-3318webappsmultiple23 abr 2021
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
23RIESGO
abrir
Exploit-DB
CMS Made Simple 2.2.15 - 'title' Cross-Site Scripting (XSS)
CVE-2021-28935webappsphp22 abr 2021
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > M
23RIESGO
abrir
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30042webappsphp22 abr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont
23RIESGO
abrir
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-31329webappsphp22 abr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
23RIESGO
abrir
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-31327webappsphp22 abr 2021
Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
23RIESGO
abrir
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30030webappsphp22 abr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
23RIESGO
abrir
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30034webappsphp22 abr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
23RIESGO
abrir
Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
CVE-2021-30039webappsphp22 abr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo
23RIESGO
abrir
Exploit-DB
Adtran Personal Phone Manager 10.8.1 - 'emailAddress' Stored Cross-Site Scripting (XSS)
CVE-2021-25679webappshardware21 abr 2021
The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. T
23RIESGO
abrir
Exploit-DBVexDay Proof
GravCMS 1.10.7 - Unauthenticated Arbitrary File Write (Metasploit)
CVE-2021-21425CRITICALwebappsphp21 abr 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
Exploit-DB
Adtran Personal Phone Manager 10.8.1 - DNS Exfiltration
CVE-2021-25681webappshardware21 abr 2021
AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. T
28RIESGO
abrir
Exploit-DB
Adtran Personal Phone Manager 10.8.1 - 'Multiple' Reflected Cross-Site Scripting (XSS)
CVE-2021-25680webappshardware21 abr 2021
The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These
23RIESGO
abrir
Exploit-DB
Multilaser Router RE018 AC1200 - Cross-Site Request Forgery (Enable Remote Access)
CVE-2021-31152webappshardware21 abr 2021
Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can ena
23RIESGO
abrir
Exploit-DB
RemoteClinic 2 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-30044webappsphp21 abr 2021
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
23RIESGO
abrir
Exploit-DB
htmly 2.8.0 - 'description' Stored Cross-Site Scripting (XSS)
CVE-2021-30637webappsmultiple15 abr 2021
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
23RIESGO
abrir
Exploit-DB
Horde Groupware Webmail 5.2.22 - Stored XSS
CVE-2021-26929webappsmultiple15 abr 2021
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.