Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
4193 exploits
Nucleihigh
GDidees CMS v3.9.1 - Arbitrary File Download
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RIESGO
abrir
Nucleimedium
OpenCATS - Open Redirect
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET pa
28RIESGO
abrir
Nucleicritical
MStore API <= 3.9.2 - Authentication Bypass
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
Nucleicritical
MStore API <= 3.9.1 - Authentication Bypass
MStore API <= 3.9.1 - Authentication Bypass
43RIESGO
abrir
Nucleicritical
PaperCut - Unauthenticated Remote Code Execution
CVE-2023-27350CRITICALbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
Nucleihigh
PaperCut NG - Authentication Bypass
CVE-2023-27351HIGHbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
88RIESGO
abrir
Nucleicritical
SPIP - Remote Command Execution
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
Nucleimedium
WordPress Core <=6.2 - Directory Traversal
WordPress Core < 6.2.1 - Directory Traversal
70RIESGO
abrir
Nucleicritical
Home Assistant Supervisor - Authentication Bypass
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for
65RIESGO
abrir
Nucleicritical
Apache Superset - Authentication Bypass
CVE-2023-27524HIGHbajo ataque
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir
Nucleicritical
Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret
Dragonfly2 vulnerable to hard coded cyptographic key
55RIESGO
abrir
Nucleimedium
ReadToMyShoe - Generation of Error Message Containing Sensitive Information
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing
36RIESGO
abrir
Nucleimedium
WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS
WordPress Redirect After Login Plugin <= 0.1.9 is vulnerable to Cross Site Scripting (XSS)
28RIESGO
abrir
Nucleicritical
PrestaShop `tshirtecommerce` Module - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
43RIESGO
abrir
Nucleihigh
tshirtecommerce PrestaShop Module - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
43RIESGO
abrir
Nucleihigh
PrestaShop TshirteCommerce - Directory Traversal
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
36RIESGO
abrir
Nucleihigh
PrestaShop tshirtecommerce - Directory Traversal
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
36RIESGO
abrir
Nucleimedium
L-Soft LISTSERV 16.5 - Cross-Site Scripting
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XS
18RIESGO
abrir
Nucleihigh
Weaver OA 9.5 - Information Disclosure
Weaver OA jx2_config.ini file access
40RIESGO
abrir
Nucleimedium
Super Socializer < 7.13.52 - Cross-Site Scripting
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Nucleicritical
Mlflow <2.3.1 - Local File Inclusion Bypass
Path Traversal: '\..\filename' in mlflow/mlflow
43RIESGO
abrir
Nucleicritical
PrestaShop xipblog - SQL Injection
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges vi
18RIESGO
abrir
Nucleimedium
Newsletter < 7.6.9 - Cross-Site Scripting
Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inj
18RIESGO
abrir
Nucleimedium
EventON <= 2.1 - Missing Authorization
EventON < 2.1.2 - Unauthenticated Event Access
50RIESGO
abrir
Nucleicritical
WooCommerce Payments - Unauthorized Admin Access
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RIESGO
abrir
Nucleimedium
Wordpress Multiple Themes - Reflected Cross-Site Scripting
Multiple Themes - Reflected XSS
18RIESGO
abrir
Nucleimedium
Ellucian Ethos Identity CAS - Cross-Site Scripting
Ellucian Ethos Identity logout cross site scripting
28RIESGO
abrir
Nucleihigh
GitLab 16.0.0 - Path Traversal
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir
Nucleicritical
Altenergy Power Control Software C1.2.5 - Remote Command Injection
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RIESGO
abrir
Nucleihigh
MinIO Cluster Deployment - Information Disclosure
CVE-2023-28432HIGHbajo ataque
Minio Information Disclosure in Cluster Deployment
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.