Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
4361 exploits
Nucleimedium
MemberSpace WordPress - Cross-Site Scripting
MemberSpace – Membership Plugin and Paid Subscriptions < 2.1.14 - Reflected XSS
28RIESGO
abrir
Nucleimedium
Relevanssi (A Better Search) <= 4.22.0 - Query Log Export
Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export
40RIESGO
abrir
Nucleimedium
WordPress SEO Tools Plugin 4.0.7 - Cross-Site Scripting
SEO Tools <= 4.0.7 - Reflected XSS
28RIESGO
abrir
Nucleihigh
WPMobile.App <= 11.56 - Open Redirect
WPMobile.App <= 11.56 - Open Redirect via 'redirect' Parameter
36RIESGO
abrir
Nucleicritical
St. Joe ERP system - SQL Injection
St. Joe ERP System SingleRowQueryConverter SQL Injection
63RIESGO
abrir
Nucleicritical
Dahua EIMS - Unauthenticated Remote Code Execution via capture_handle
Dahua EIMS capture_handle.action RCE
68RIESGO
abrir
Nucleimedium
Studiocart <= 2.9.0 - Cross-Site Scripting
Studiocart <= 2.9.0 - Reflected XSS
36RIESGO
abrir
Nucleihigh
Mlflow < 2.9.2 - Path Traversal
Path Traversal Vulnerability in mlflow/mlflow
36RIESGO
abrir
Nucleicritical
MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
85RIESGO
abrir
Nucleihigh
Gradio 4.3-4.12 - Local File Read
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RIESGO
abrir
Nucleicritical
NotificationX <= 2.8.2 - SQL Injection
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir
Nucleihigh
ConnectWise ScreenConnect <= 23.9.7 - Path Traversal
CVE-2024-1708HIGHbajo ataqueransomware
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RIESGO
abrir
Nucleicritical
ConnectWise ScreenConnect 23.9.7 - Authentication Bypass
CVE-2024-1709CRITICALbajo ataqueransomware
Authentication bypass using an alternate path or channel
100RIESGO
abrir
Nucleihigh
Gradio > 4.19.1 UploadButton - Path Traversal
Local File Inclusion in gradio-app/gradio
58RIESGO
abrir
Nucleihigh
Tutor LMS <= 2.1.10 - SQL Injection
Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection
36RIESGO
abrir
Nucleimedium
Cisco Finesse - Server-Side Request Forgery (SSRF)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t
61RIESGO
abrir
Nucleicritical
Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
43RIESGO
abrir
Nucleihigh
Check Point Quantum Gateway - Information Disclosure
CVE-2024-24919HIGHbajo ataqueransomware
Information disclosure
100RIESGO
abrir
Nucleicritical
Unauthenticated Remote Code Execution – Bricks <= 1.9.6
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
Nucleimedium
Liferay Portal - Open Redirect
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 be
28RIESGO
abrir
Nucleicritical
ZenML ZenML Server - Improper Authentication
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because t
58RIESGO
abrir
Nucleihigh
WyreStorm Apollo VX20 - Information Disclosure
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password
75RIESGO
abrir
Nucleihigh
Linksys RE7000 - Command Injection
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter
41RIESGO
abrir
Nucleimedium
Fujian Kelixin Communication - Command Injection
Fujian Kelixin Communication Command and Dispatch Platform pwd_update.php sql injection
28RIESGO
abrir
Nucleihigh
Avid NEXIS Agent - Arbitrary File Read
Authenticated Arbitrary File Read affecting Avid NEXIS
36RIESGO
abrir
Nucleihigh
ReCrystallize Server - Authentication Bypass
ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind
48RIESGO
abrir
Nucleicritical
InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir
Nucleihigh
SOPlanning - Remote Code Execution
Remote Code Execution through File Upload in SOPlanning before 1.52.02
43RIESGO
abrir
Nucleicritical
TeamCity < 2023.11.4 - Authentication Bypass
CVE-2024-27198CRITICALbajo ataqueransomware
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
Nucleihigh
TeamCity < 2023.11.4 - Authentication Bypass
CVE-2024-27199HIGHbajo ataqueransomware
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.