Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
4201 exploits
Nucleihigh
Xiaomi Mi WiFi R3G Routers - Local file Inclusion
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerabilit
50RIESGO
abrir
Nucleimedium
Ignite Realtime Openfire <4.42 - Local File Inclusion
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the
23RIESGO
abrir
Nucleicritical
Ignite Realtime Openfire <=4.4.2 - Server-Side Request Forgery
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allo
30RIESGO
abrir
Nucleihigh
DOMOS 5.5 - Local File Inclusion
The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.
23RIESGO
abrir
Nucleicritical
strapi CMS <3.0.0-beta.17.5 - Admin Password Reset
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
Nucleihigh
Allied Telesis AT-GS950/8 - Local File Inclusion
A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] al
23RIESGO
abrir
Nucleicritical
Xfilesharing 2.5.1 - Arbitrary File Upload
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951
30RIESGO
abrir
Nucleimedium
MicroStrategy Library <11.1.3 - Cross-Site Scripting
Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.
18RIESGO
abrir
Nucleimedium
Cisco RV110W RV130W RV215W Router - Information leakage
Cisco RV110W, RV130W, and RV215W Routers Unauthenticated syslog File Access Vulnerability
40RIESGO
abrir
Nucleimedium
WordPress Hero Maps Premium <=2.2.1 - Cross-Site Scripting
The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index
18RIESGO
abrir
Nucleimedium
Rumpus FTP Web File Manager 8.2.9.1 - Cross-Site Scripting
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker ca
43RIESGO
abrir
Nucleilow
Huawei Firewall - Local File Inclusion
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100,
18RIESGO
abrir
Nucleimedium
Cisco Small Business 200,300 and 500 Series Switches - Open Redirect
Cisco Small Business Series Switches Open Redirect Vulnerability
53RIESGO
abrir
Nucleicritical
Citrix ADC and Gateway - Directory Traversal
CVE-2019-19781CRITICALbajo ataqueransomware
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
Nucleihigh
TOTOLINK/Realtek Routers - Information Disclosure
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attacker
18RIESGO
abrir
Nucleihigh
TOTOLINK/Realtek Routers - Information Disclosure
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext admin
18RIESGO
abrir
Nucleihigh
TOTOLINK Realtek SD Routers - Remote Command Injection
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCm
23RIESGO
abrir
Nucleicritical
TOTOLINK/Realtek Routers - CAPTCHA Bypass
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"}
23RIESGO
abrir
Nucleimedium
phpMyChat-Plus 1.98 - Cross-Site Scripting
phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the
23RIESGO
abrir
Nucleimedium
WordPress Email Subscribers & Newsletters <4.2.3 - Arbitrary File Retrieval
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa
70RIESGO
abrir
Nucleihigh
TVT NVMS 1000 - Local File Inclusion
CVE-2019-20085HIGHbajo ataque
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
Nucleimedium
WordPress Laborator Neon Theme 2.0 - Cross-Site Scripting
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q paramete
18RIESGO
abrir
Nucleihigh
Simple Employee Records System 1.0 - Unrestricted File Upload
uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension
18RIESGO
abrir
Nucleimedium
WordPress CTHthemes - Cross-Site Scripting
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflecte
18RIESGO
abrir
Nucleihigh
Pandora FMS 7.0NG - Remote Command Injection
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary O
30RIESGO
abrir
Nucleicritical
Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Remote Code Execution
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attack
18RIESGO
abrir
Nucleicritical
InfluxDB <1.7.6 - Authentication Bypass
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.
50RIESGO
abrir
Nucleicritical
Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update
Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update
43RIESGO
abrir
Nucleihigh
Abandoned Cart Lite for WooCommerce < 5.2.0 - Cross-Site Scripting
Abandoned Cart Lite for WooCommerce < 5.2.0 and Abandoned Cart Pro for WooCommerce < 7.13.0 - Stored Cross-Site Scripting
36RIESGO
abrir
Nucleicritical
WordPress Advanced Access Manager - Path Traversal
Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read
43RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.