Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
4350 exploits
Nucleicritical
ASUS DSL-AC88U - Authentication Bypass
ASUS Router - Improper Authentication
55RIESGO
abrir
Nucleimedium
NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
40RIESGO
abrir
Nucleimedium
Fides Privacy Center ≤ 2.39.1 - Server-Side URL Disclosure
Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
28RIESGO
abrir
Nucleicritical
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
43RIESGO
abrir
Nucleihigh
Flowise 1.6.5 - Authentication Bypass
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted sc
68RIESGO
abrir
Nucleihigh
F-logic DataCube3 - SQL Injection
SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the
48RIESGO
abrir
Nucleimedium
CHAOS 5.0.1 'sendCommandHandler' - Cross-Site Scripting
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via th
28RIESGO
abrir
Nucleicritical
CData API Server < 23.4.8844 - Path Traversal
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedde
63RIESGO
abrir
Nucleicritical
CData Connect < 23.4.8846 - Path Traversal
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded J
43RIESGO
abrir
Nucleihigh
CData Arc < 23.4.8839 - Path Traversal
A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty
36RIESGO
abrir
Nucleihigh
CData Sync < 23.4.8843 - Path Traversal
A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jett
36RIESGO
abrir
Nucleicritical
XWiki < 4.10.20 - Remote code execution
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RIESGO
abrir
Nucleihigh
Apache OFBiz Directory Traversal - Remote Code Execution
CVE-2024-32113CRITICALbajo ataque
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
Nucleihigh
Apache ActiveMQ 6.x < 6.1.2 - Broken Access Control
Apache ActiveMQ: Jolokia and REST API were not secured with default configuration
36RIESGO
abrir
Nucleicritical
WordPress Realtyna Organic IDX Plugin <= 4.14.4 - SQL Injection
WordPress Realtyna Organic IDX plugin + WPL Real Estate plugin <= 4.14.4 - Unauthenticated SQL Injection vulnerability
43RIESGO
abrir
Nucleicritical
Stash < 0.26.0 - SQL Injection
Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.
28RIESGO
abrir
Nucleicritical
H3C ER8300G2-X - Password Disclosure
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RIESGO
abrir
Nucleimedium
Popup4Phone <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
Popup4Phone <= 1.3.2 - Unauthenticated Stored XSS
28RIESGO
abrir
Nucleicritical
Chuanhu Chat - Directory Traversal
Path Traversal in gaizhenbiao/chuanhuchatgpt
43RIESGO
abrir
Nucleihigh
RaidenMAILD Mail Server v.4.9.4 - Path Traversal
Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensi
36RIESGO
abrir
Nucleicritical
Mura/Masa CMS - SQL Injection
MasaCMS SQL Injection vulnerability
85RIESGO
abrir
Nucleicritical
Change Detection - Server Side Template Injection
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RIESGO
abrir
Nucleicritical
WP-Recall <= 16.26.5 - SQL Injection
WordPress WP-Recall plugin <= 16.26.5 - SQL Injection vulnerability
43RIESGO
abrir
Nucleicritical
D-Link Network Attached Storage - Backdoor Account
CVE-2024-3272CRITICALbajo ataque
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
100RIESGO
abrir
Nucleicritical
D-Link Network Attached Storage - Command Injection and Backdoor Account
CVE-2024-3273HIGHbajo ataque
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RIESGO
abrir
Nucleicritical
CyberPower - Missing Authentication
CyberPower PowerPanel Enterprise Missing Authentication
43RIESGO
abrir
Nucleihigh
CyberPower < v2.8.3 - SQL Injection
CyberPower PowerPanel Enterprise SQL Injection
36RIESGO
abrir
Nucleihigh
CyberPower - SQL Injection
CyberPower PowerPanel Enterprise SQL Injection
36RIESGO
abrir
Nucleihigh
CyberPower - SQL Injection
CyberPower PowerPanel Enterprise SQL Injection
36RIESGO
abrir
Nucleihigh
CyberPower < v2.8.3 - SQL Injection
CyberPower PowerPanel Enterprise SQL Injection
36RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.