Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
4361 exploits
Nucleimedium
WordPress Gallery <2.0.0 - Cross-Site Scripting
Gallery < 2.0.0 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleicritical
Youzify < 1.2.0 - Unauthenticated SQLi
Youzify < 1.2.0 - Unauthenticated SQLi
18RIESGO
abrir
Nucleicritical
WordPress eaSYNC Booking <1.1.16 - Arbitrary File Upload
eaSYNC < 1.1.16 - Unauthenticated Arbitrary File Upload
23RIESGO
abrir
Nucleimedium
WordPress Sensei LMS <4.5.0 - Information Disclosure
Sensei LMS < 4.5.0 - Unauthenticated Private Messages Disclosure via Rest API
18RIESGO
abrir
Nucleimedium
Microweber < 1.2.17 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in microweber/microweber
28RIESGO
abrir
Nucleihigh
Oracle WebLogic Server Local File Inclusion
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RIESGO
abrir
Nucleihigh
Oracle E-Business Suite <=12.2 - Authentication Bypass
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Ea
58RIESGO
abrir
Nucleicritical
Apache APISIX - Remote Code Execution
CVE-2022-24112CRITICALbajo ataque
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
Nucleihigh
Casdoor 1.13.0 - Unauthenticated SQL Injection
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RIESGO
abrir
Nucleihigh
Shibboleth OIDC OP <3.0.4 - Server-Side Request Forgery
The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insuff
18RIESGO
abrir
Nucleihigh
FreeIPA - XML Entity Injection
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a
60RIESGO
abrir
Nucleimedium
PKP Open Journal Systems 2.4.8-3.3 - Cross-Site Scripting
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to
38RIESGO
abrir
Nucleicritical
Atom CMS v2.0 - SQL Injection
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
50RIESGO
abrir
Nucleicritical
VoipMonitor - Pre-Auth SQL Injection
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administra
30RIESGO
abrir
Nucleihigh
Cuppa CMS v1.0 - SQL injection
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t
18RIESGO
abrir
Nucleihigh
Cuppa CMS v1.0 - SQL injection
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=c
18RIESGO
abrir
Nucleihigh
Cuppa CMS v1.0 - SQL injection
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t
18RIESGO
abrir
Nucleihigh
Apache Airflow OS Command Injection
Apache Airflow: RCE in example DAGs
40RIESGO
abrir
Nucleimedium
SmarterTools SmarterTrack - Cross-Site Scripting
Reflective XSS on SmarterTrack v100.0.8019.14010
36RIESGO
abrir
Nucleimedium
Transposh WordPress Translation <= 1.0.8 - Unauthenticated Settings Change
Transposh WordPress Translation <= 1.0.9.6 - Unauthorized Settings Change
28RIESGO
abrir
Nucleimedium
WordPress Transposh <=1.0.8.1 - Information Disclosure
Transposh WordPress Translation <= 1.0.9.6 - Sensitive Information Disclosure
28RIESGO
abrir
Nucleicritical
AudioCodes Device Manager Express - SQL Injection
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injec
68RIESGO
abrir
Nucleicritical
Open Web Analytics 1.7.3 - Remote Code Execution
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
Nucleicritical
Garage Management System 1.0 - SQL Injection
SourceCodester Garage Management System login.php sql injection
36RIESGO
abrir
Nucleimedium
ManageEngine ADSelfService Plus <6121 - Stored Cross-Site Scripting
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock
18RIESGO
abrir
Nucleimedium
Zimbra Collaboration Suite < 8.8.15 - Improper Encoding
CVE-2022-24682MEDIUMbajo ataqueransomware
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), a
70RIESGO
abrir
Nucleihigh
Icinga Web 2 - Arbitrary File Disclosure
Path traversal in Icinga Web 2
78RIESGO
abrir
Nucleicritical
GeoServer <1.2.2 - Remote Code Execution
CVE-2022-24816CRITICALbajo ataque
Improper Control of Generation of Code in jai-ext
100RIESGO
abrir
Nucleimedium
XWiki < 12.10.11, 13.4.4 & 13.9-rc-1 - Information Disclosure
Unauthenticated user can retrieve the list of users through uorgsuggest.vm
28RIESGO
abrir
Nucleihigh
Flyte Console <0.52.0 - Server-Side Request Forgery
Server-Side Request Forgery in FlyteConsole
48RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.