Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.859exploits catalogados
32.149CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleimedium
WSO2 - Cross-Site Scripting
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,
60RIESGO
abrir
Nucleicritical
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.
18RIESGO
abrir
Nucleicritical
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.
18RIESGO
abrir
Nucleihigh
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.
18RIESGO
abrir
Nucleihigh
Complete Online Job Search System 1.0 - SQL Injection
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.
18RIESGO
abrir
Nucleihigh
Complete Online Job Search System 1.0 - SQL Injection
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.
18RIESGO
abrir
Nucleihigh
Complete Online Job Search System 1.0 - SQL Injection
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.
18RIESGO
abrir
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?act
18RIESGO
abrir
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.
18RIESGO
abrir
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id
18RIESGO
abrir
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.
18RIESGO
abrir
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php
18RIESGO
abrir
Nucleicritical
Hospital Management System 1.0 - SQL Injection
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doc
18RIESGO
abrir
Nucleimedium
Open edX <2022-06-06 - Cross-Site Scripting
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
18RIESGO
abrir
Nucleicritical
Sophos Firewall <= 19.0 MR1 - Remote Code Execution
CVE-2022-3236CRITICALbajo ataque
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewa
95RIESGO
abrir
Nucleicritical
Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3ge
23RIESGO
abrir
Nucleimedium
Microweber <1.3.2 - Cross-Site Scripting
HTML code Injection in template search keyword in microweber/microweber
28RIESGO
abrir
Nucleicritical
MSNSwitch Firmware MNT.2408 - Authentication Bypass
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog
60RIESGO
abrir
Nucleihigh
Lin CMS Spring Boot - Default JWT Token
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions w
18RIESGO
abrir
Nucleimedium
u5cms v8.3.5 - Open Redirect
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser t
18RIESGO
abrir
Nucleicritical
AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection
AWP Classifieds Plugin < 4.3 - Unauthenticated SQLi
43RIESGO
abrir
Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master
43RIESGO
abrir
Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master
43RIESGO
abrir
Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master
43RIESGO
abrir
Nucleimedium
NUUO NVRsolo Video Recorder 03.06.02 - Cross-Site Scripting
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi
18RIESGO
abrir
Nucleihigh
Powertek Firmware <3.30.30 - Authorization Bypass
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
68RIESGO
abrir
Nucleicritical
WordPress Accordions - Unauthenticated Settings Update
WordPress Accordions plugin <= 2.0.2 - Unauthenticated WordPress Options Change vulnerability
43RIESGO
abrir
Nucleihigh
Apache Spark UI - Remote Command Injection
CVE-2022-33891HIGHbajo ataque
Apache Spark shell command injection vulnerability via Spark UI
100RIESGO
abrir
Nucleihigh
WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Read
WordPress MultiSafepay plugin for WooCommerce plugin <= 4.13.1 - Unauthenticated Arbitrary File Read vulnerability
28RIESGO
abrir
Nucleicritical
WordPress Visitor Statistics <=5.7 - SQL Injection
WordPress WP Visitor Statistics plugin <= 5.7 - Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities
43RIESGO
abrir
anteriorpágina 101 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.