Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleicritical
MinIO Operator Console Authentication Bypass
Authentication bypass issue in the Operator Console
48RIESGO
abrir
Nucleihigh
Metabase - Local File Inclusion
CVE-2021-41277CRITICALbajo ataque
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RIESGO
abrir
Nucleihigh
pfSense - Arbitrary File Write
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data abo
40RIESGO
abrir
Nucleihigh
ECOA Building Automation System - Directory Traversal Content Disclosure
ECOA BAS controller - Path Traversal-1
58RIESGO
abrir
Nucleihigh
ECOA Building Automation System - Arbitrary File Retrieval
ECOA BAS controller - Path Traversal-3
41RIESGO
abrir
Nucleimedium
Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting
Microsoft Exchange Server Spoofing Vulnerability
70RIESGO
abrir
Nucleihigh
Payara Micro Community 5.2021.6 Directory Traversal
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RIESGO
abrir
Nucleicritical
QVIS NVR/DVR - Remote Code Execution
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
18RIESGO
abrir
Nucleimedium
FlatPress 1.2.1 - Stored Cross-Site Scripting
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaS
18RIESGO
abrir
Nucleihigh
ECShop 4.1.0 - SQL Injection
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
18RIESGO
abrir
Nucleimedium
JustWriting - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow rem
18RIESGO
abrir
Nucleihigh
SAS/Internet 9.4 1520 - Local File Inclusion
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the app
18RIESGO
abrir
Nucleihigh
PuneethReddyHC action.php SQL Injection
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId
23RIESGO
abrir
Nucleicritical
PuneethReddyHC Online Shopping System homeaction.php SQL Injection
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php c
30RIESGO
abrir
Nucleicritical
TP-Link - OS Command Injection
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to r
60RIESGO
abrir
Nucleihigh
openSIS Student Information System 8.0 SQL Injection
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TR
43RIESGO
abrir
Nucleicritical
CraftCMS SEOmatic - Server-Side Template Injection
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Si
23RIESGO
abrir
Nucleicritical
Apache Log4j2 Remote Code Injection
CVE-2021-44228CRITICALbajo ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Nucleihigh
WAVLINK AC1200 - Information Disclosure
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can al
18RIESGO
abrir
Nucleicritical
3DPrint Lite < 1.9.1.5 - Arbitrary File Upload
3DPrint Lite < 1.9.1.5 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir
Nucleicritical
Rosario Student Information System Unauthenticated SQL Injection
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allow
55RIESGO
abrir
Nucleimedium
Apache Superset <=1.3.2 - Default Login
API sensitive information leak
18RIESGO
abrir
Nucleihigh
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
36RIESGO
abrir
Nucleicritical
ZoomSounds Plugin - Unauthenticated Arbitrary File Upload
ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
43RIESGO
abrir
Nucleicritical
Zoho ManageEngine Desktop Central - Remote Code Execution
CVE-2021-44515CRITICALbajo ataque
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server
95RIESGO
abrir
Nucleimedium
Open Redirect in Host Authorization Middleware
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host"
18RIESGO
abrir
Nucleicritical
Ivanti EPM Cloud Services Appliance Code Injection
CVE-2021-44529CRITICALbajo ataqueransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RIESGO
abrir
Nucleicritical
Employee Records System 1.0 - Unauthenticated File Upload RCE
Employee Records System v1.0 Arbitrary File Upload RCE
63RIESGO
abrir
Nucleihigh
Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download
Longjing Technology BEMS API <= 1.21 Remote Arbitrary File Download
36RIESGO
abrir
Nucleimedium
Thinfinity VirtualUI User Enumeration
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RIESGO
abrir
anteriorpágina 122 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.