Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
4361 exploits
Nucleicritical
Cloudpanel 2 < 2.3.1 - Remote Code Execution
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
85RIESGO
abrir
Nucleihigh
Intelbras Switch - Information Disclosure
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to downlo
50RIESGO
abrir
Nucleihigh
QloApps 1.6.0 - SQL Injection
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_p
18RIESGO
abrir
Nucleimedium
Webkul QloApps 1.6.0 - Cross-site Scripting
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a
18RIESGO
abrir
Nucleimedium
Webkul QloApps 1.6.0 - Cross-site Scripting
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a
18RIESGO
abrir
Nucleimedium
Adiscon LogAnalyzer v.4.1.13 - Cross-Site Scripting
A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to exec
38RIESGO
abrir
Nucleimedium
POS Codekop v2.0 - Cross Site Scripting
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RIESGO
abrir
Nucleihigh
POS Codekop v2.0 - Broken Authentication
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to down
30RIESGO
abrir
Nucleicritical
CAREL Boss Mini <= 1.4.0 - Local File Inclusion
Boss Mini document file inclusion
78RIESGO
abrir
Nucleimedium
Juniper Devices - Remote Code Execution
CVE-2023-36844MEDIUMbajo ataque
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RIESGO
abrir
Nucleicritical
Juniper J-Web - Remote Code Execution
CVE-2023-36845CRITICALbajo ataque
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
Nucleicritical
MOVEit Transfer - SQL Injection
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.
40RIESGO
abrir
Nucleicritical
Honeywell PM43 Printers - Command Injection
Printer web page invalid command execution
75RIESGO
abrir
Nucleihigh
Avaya Aura Device Services - OS Command Injection
Avaya Aura Device Services Remote Code Execution
56RIESGO
abrir
Nucleicritical
CasaOS < 0.4.4 - Authentication Bypass via Internal IP
Incorrect identification of source IP addresses in CasaOS
43RIESGO
abrir
Nucleicritical
CasaOS < 0.4.4 - Authentication Bypass via Random JWT Token
Weak json web token (JWT) secrets in CasaOS
43RIESGO
abrir
Nucleihigh
Piwigo 13.7.0 - SQL Injection
Piwigo SQL Injection vulnerability in "User-Agent"
36RIESGO
abrir
Nucleihigh
XWiki Platform - Remote Code Execution
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui
65RIESGO
abrir
Nucleihigh
Copyparty <= 1.8.2 - Directory Traversal
Path traversal in copyparty
48RIESGO
abrir
Nucleimedium
Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scripting
CVE-2023-37580MEDIUMbajo ataque
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
70RIESGO
abrir
Nucleihigh
Issabel PBX 4.0.0-6 - Directory Listing
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
18RIESGO
abrir
Nucleicritical
Online Piggery Management System v1.0 - Unauthenticated File Upload
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send
43RIESGO
abrir
Nucleimedium
EyouCms v1.6.3 - Information Disclosure
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/re
23RIESGO
abrir
Nucleicritical
MLflow Absolute Path Traversal
Absolute Path Traversal in mlflow/mlflow
55RIESGO
abrir
Nucleicritical
NextGen Mirth Connect - Remote Code Execution
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary com
40RIESGO
abrir
Nucleimedium
IceWarp Webmail Server v10.2.1 - Cross Site Scripting
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
18RIESGO
abrir
Nucleimedium
Ninja Forms < 3.6.26 - Cross-Site Scripting
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RIESGO
abrir
Nucleimedium
Contact Form Generator <= 2.5.5 - Cross-Site Scripting
WordPress Contact Form Generator Plugin <= 2.5.5 is vulnerable to Cross Site Scripting (XSS)
36RIESGO
abrir
Nucleicritical
HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation
WordPress HT Mega Absolute Addons for Elementor plugin <= 2.2.0 - Unauthenticated Privilege Escalation vulnerability
43RIESGO
abrir
Nucleicritical
Ivanti Sentry - Authentication Bypass
CVE-2023-38035CRITICALbajo ataqueransomware
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.