Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
4201 exploits
Nucleimedium
Zoho manageengine - Cross-Site Scripting
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network
40RIESGO
abrir
Nucleimedium
TOTOLINK A3002RU 1.0.8 - Information Disclosure
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password
18RIESGO
abrir
Nucleihigh
Apache Tika < 1.1.8 - Header Command Injection
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Nucleicritical
Fortinet FortiOS - Credentials Disclosure
CVE-2018-13379CRITICALbajo ataqueransomware
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Nucleimedium
Fortinet FortiOS - Cross-Site Scripting
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and
40RIESGO
abrir
Nucleimedium
Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RIESGO
abrir
Nucleimedium
Synacor Zimbra Collaboration Suite Collaboration <8.8.11 - Cross-Site Scripting
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
18RIESGO
abrir
Nucleicritical
VelotiSmart Wifi - Directory Traversal
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RIESGO
abrir
Nucleimedium
Orange Forum 1.4.0 - Open Redirect
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
18RIESGO
abrir
Nucleimedium
Django - Open Redirect
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
23RIESGO
abrir
Nucleicritical
Responsive filemanager 9.13.1 Server-Side Request Forgery
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RIESGO
abrir
Nucleihigh
cgit < 1.2.1 - Directory Traversal
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned
60RIESGO
abrir
Nucleicritical
Kaseya VSA < 9.5.7 - Credential Disclosure via Windows Agent
CVE-2021-30116CRITICALbajo ataqueransomware
Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
95RIESGO
abrir
Nucleicritical
Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code Execution
Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5
55RIESGO
abrir
Nucleicritical
Apache OFBiz <17.12.07 - Arbitrary Code Execution
Unsafe deserialization in Apache OFBiz
60RIESGO
abrir
Nucleimedium
Php-mod/curl Library <2.3.2 - Cross-Site Scripting
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key paramet
28RIESGO
abrir
Nucleimedium
Sidekiq <=6.2.0 - Cross-Site Scripting
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explore
18RIESGO
abrir
Nucleihigh
Intelbras WIN 300/WRN 342 - Credentials Disclosure
The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover creden
30RIESGO
abrir
Nucleicritical
ZEROF Web Server 1.0 - SQL Injection
ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
18RIESGO
abrir
Nucleicritical
IPeakCMS 3.5 - SQL Injection
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
43RIESGO
abrir
Nucleihigh
ffay lanproxy Directory Traversal
ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection t
23RIESGO
abrir
Nucleihigh
Dzzoffice 2.02.1 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers
18RIESGO
abrir
Nucleimedium
Knowage Suite 7.3 - Cross-Site Scripting
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrar
18RIESGO
abrir
Nucleicritical
VoipMonitor <24.61 - Remote Code Execution
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RIESGO
abrir
Nucleihigh
Ivanti Avalanche 6.3.2 - Local File Inclusion
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal
40RIESGO
abrir
Nucleicritical
PrestaShop 1.7.7.0 - SQL Injection
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller
23RIESGO
abrir
Nucleimedium
Microsoft Exchange Server - Cross-Site Scripting
Microsoft Exchange Server Remote Code Execution Vulnerability
50RIESGO
abrir
Nucleimedium
CHIYU TCP/IP Converter - Carriage Return Line Feed Injection
A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology I
23RIESGO
abrir
Nucleimedium
CHIYU TCP/IP Converter - Cross-Site Scripting
Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU T
40RIESGO
abrir
Nucleicritical
Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution
CVE-2021-3129CRITICALbajo ataqueransomware
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.