Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
4361 exploits
Nucleicritical
ProFTPd-1.3.3c - Backdoor Command Execution
ProFTPD 1.3.3c Backdoor Command Execution
63RIESGO
abrir
Nucleimedium
MySQL - Authentication Bypass
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir
Nucleihigh
Memcached Server SASL Authentication - Remote Code Execution
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of
48RIESGO
abrir
Nucleicritical
Cisco Smart Install - Configuration Download
CVE-2018-0171HIGHbajo ataque
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica
100RIESGO
abrir
Nucleihigh
Apache HTTP Server - NULL Pointer Dereference
mod_md, DoS via Coredumps on specially crafted requests
30RIESGO
abrir
Nucleicritical
NTPsec > 1.1.3 - 'ctl_getitem' Out-of-Bounds Read
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read
50RIESGO
abrir
Nucleihigh
PostgreSQL 9.3-12.3 Authenticated Remote Code Execution
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
Nucleicritical
Oracle WebLogic Server - Remote Code Execution (Insecure Deserialization)
CVE-2020-14644CRITICALbajo ataque
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
Nucleicritical
Oracle WebLogic Server - Remote Code Execution
CVE-2020-2883CRITICALbajo ataque
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
Nucleicritical
IBM Data Risk Manager - Hardcoded Credentials
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RIESGO
abrir
Nucleicritical
OpenSMTPD 6.4.0-6.6.1 - Remote Code Execution
CVE-2020-7247CRITICALbajo ataque
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Nucleihigh
Veritas Backup Exec - Broken Authentication
CVE-2021-27877HIGHbajo ataqueransomware
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RIESGO
abrir
Nucleicritical
SolarWinds Serv-U FTP - Remote Code Execution
CVE-2021-35211CRITICALbajo ataqueransomware
Serv-U Remote Memory Escape Vulnerability
100RIESGO
abrir
Nucleicritical
RealTek AP Router SDK - Arbitrary Command Injection
CVE-2021-35394CRITICALbajo ataque
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as
95RIESGO
abrir
Nucleihigh
PowerDNS Authoritative Server - Denial of Service
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE
30RIESGO
abrir
Nucleihigh
Oracle WebLogic Server - Unauthorized Access
CVE-2023-21839HIGHbajo ataque
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
Nucleicritical
VMWare Aria Operations - Remote Code Execution
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RIESGO
abrir
Nucleicritical
Acronis Cyber Infrastructure - Default Password
CVE-2023-45249CRITICALbajo ataque
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
85RIESGO
abrir
Nucleicritical
Apache ActiveMQ - Remote Code Execution
CVE-2023-46604CRITICALbajo ataqueransomware
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
Nucleimedium
ManageEngine Firewall Analyzer 7.2 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inje
38RIESGO
abrir
Nucleimedium
Axigen Mail Server Filename Directory Traversal
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote att
60RIESGO
abrir
Nucleimedium
Forescout CounterACT 6.3.4.1 - Open Redirect
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to
38RIESGO
abrir
Nucleimedium
TikiWiki CMS Groupware v8.3 - Open Redirect
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frame
43RIESGO
abrir
Nucleimedium
WordPress Integrator 1.32 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allo
38RIESGO
abrir
Nucleimedium
WordPress Plugin Age Verification v0.4 - Open Redirect
Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows
43RIESGO
abrir
Nucleicritical
Apache Struts2 S2-012 RCE
Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute
40RIESGO
abrir
Nucleimedium
Apache Struts - Multiple Open Redirection Vulnerabilities
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to
60RIESGO
abrir
Nucleicritical
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
CVE-2013-2251CRITICALbajo ataque
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir
Nucleimedium
WordPress Plugin Uploader 1.0.4 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow
38RIESGO
abrir
Nucleimedium
Telaen => v1.3.1 - Open Redirect
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victim
43RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.