Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
4361 exploits
Nucleihigh
DATAGERRY - Improper Access Control
The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability.
48RIESGO
abrir
Nucleicritical
openSIS Classic v9.1 - SQL Injection
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The
63RIESGO
abrir
Nucleimedium
TOTOLINK CX-A3002RU - Remote Code Execution
An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300R
28RIESGO
abrir
Nucleicritical
CyberPanel - Command Injection
CVE-2024-51378CRITICALbajo ataqueransomware
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
Nucleicritical
ZoneMinder v1.37.* <= 1.37.64 - SQL Injection
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RIESGO
abrir
Nucleimedium
Changedetection.io <= 0.47.4 - Path Traversal
changedetection.io Path Traversal vulnerability
28RIESGO
abrir
Nucleicritical
CyberPanel v2.3.6 Pre-Auth Remote Code Execution
CVE-2024-51567CRITICALbajo ataqueransomware
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RIESGO
abrir
Nucleicritical
CyberPanel - Command Injection
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RIESGO
abrir
Nucleimedium
iTop - User Enumeration via REST Endpoint
Users enumeration allowed through Rest API in Combodo iTop
36RIESGO
abrir
Nucleimedium
Brother MFC-L9570CDW - Information Disclosure
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RIESGO
abrir
Nucleicritical
Brother Printers – Authentication Bypass via Default Admin Password
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RIESGO
abrir
Nucleicritical
ServiceNow - Incomplete Input Validation
CVE-2024-5217CRITICALbajo ataque
Incomplete Input Validation in GlideExpression Script
100RIESGO
abrir
Nucleimedium
FleetCart 4.1.1 - Information Disclosure
EnvaySoft FleetCart information disclosure
33RIESGO
abrir
Nucleicritical
My Geo Posts Free <= 1.2 - PHP Object Injection
WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
63RIESGO
abrir
Nucleicritical
Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injection
SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
65RIESGO
abrir
Nucleimedium
Ganglia Web Interface (v3.7.3 - v3.7.6) - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows atta
28RIESGO
abrir
Nucleimedium
Ganglia Web Interface (v3.7.3 - v3.7.5) - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows
28RIESGO
abrir
Nucleihigh
Kerio Control v9.2.5 - CRLF Injection
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertE
41RIESGO
abrir
Nucleicritical
Dolibarr ERP CMS `list.php` - SQL Injection
Multiple vulnerabilities in DOLIBARR's ERP CMS
55RIESGO
abrir
Nucleimedium
WordPress Events Calendar 6.8.2.1 - Information Disclosure
The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure
28RIESGO
abrir
Nucleihigh
Devika - Local File Inclusion
Local File Read in stitionai/devika
36RIESGO
abrir
Nucleicritical
SSL VPN Session Hijacking
CVE-2024-53704HIGHbajo ataqueransomware
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir
Nucleicritical
Mongoose < 8.8.3 - Remote Code Execution
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir
Nucleihigh
Discourse Backup File Disclosure Via Default Nginx Configuration
Potential Backup file leaked via Nginx in Discourse
41RIESGO
abrir
Nucleilow
SickChill - Open Redirect
GHSL-2024-288: SickChill open redirect in login
23RIESGO
abrir
Nucleihigh
SEH utnserver Pro/ProMAX/INU-100 20.1.22 - Cross-Site Scripting
Stored Cross-Site Scripting in SEH Computertechnik utnserver Pro
36RIESGO
abrir
Nucleihigh
SEH utnserver Pro/ProMAX/INU-100 20.1.22 - File Exposure
Authenticated Command Injection
36RIESGO
abrir
Nucleihigh
Hurrakify <= 2.4 - Server-Side Request Forgery
WordPress Hurrakify plugin <= 2.4 - Server Side Request Forgery (SSRF) vulnerability
36RIESGO
abrir
Nucleihigh
Radio Player <= 2.0.82 - Server-Side Request Forgery
WordPress Radio Player plugin <= 2.0.83 - Server Side Request Forgery (SSRF) vulnerability
36RIESGO
abrir
Nucleimedium
ipTIME A2004 - Unauthorized Access
An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensiti
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.