Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleimedium
Web2py URL - Open Redirect
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirec
28RIESGO
abrir
Nucleicritical
KubePi JwtSigKey - Admin Authentication Bypass
KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT token
55RIESGO
abrir
Nucleihigh
KubePi <= v1.6.4 LoginLogsSearch - Unauthorized Access
KubePi is vulnerable to missing authorization
36RIESGO
abrir
Nucleicritical
KubeOperator Foreground `kubeconfig` - File Download
KubeOperator is vulnerable to unauthorized access to system API
48RIESGO
abrir
Nucleicritical
Atlassian Confluence - Privilege Escalation
CVE-2023-22515CRITICALbajo ataqueransomware
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
Nucleicritical
Atlassian Confluence Server - Improper Authorization
CVE-2023-22518CRITICALbajo ataqueransomware
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir
Nucleilow
Directorist < 7.5.4 - Local File Inclusion
Directorist < 7.5.4 - Admin+ LFI
23RIESGO
abrir
Nucleicritical
Atlassian Confluence - Remote Code Execution
CVE-2023-22527CRITICALbajo ataqueransomware
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
Nucleihigh
WordPress Product Addons & Fields for WooCommerce < 32.0.7 - Cross-Site Scripting
Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleihigh
SecurePoint UTM 12.x Session ID Leak
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid infor
36RIESGO
abrir
Nucleihigh
Strapi Versions <=4.5.5 - SSTI to Remote Code Execution
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RIESGO
abrir
Nucleimedium
Tiempo.com <= 0.1.2 - Cross-Site Scripting
Tiempo.com <= 0.1.2 - Reflected XSS
18RIESGO
abrir
Nucleihigh
Strapi Versions <=4.5.6 - Authentication Bypass
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login pro
36RIESGO
abrir
Nucleimedium
Securepoint UTM - Leaking Remote Memory Contents
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information dis
28RIESGO
abrir
Nucleihigh
SugarCRM Unauthenticated - Remote Code Execution
CVE-2023-22952HIGHbajo ataque
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because o
100RIESGO
abrir
Nucleihigh
Cellinx NVT Web Server - Local File Disclosure
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFi
38RIESGO
abrir
Nucleimedium
wpForo Forum <= 2.1.8 - Cross-Site Scripting
wpForo Forum < 2.1.9 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleimedium
Art Gallery Management System Project v1.0 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RIESGO
abrir
Nucleicritical
SolarView Compact 6.00 - OS Command Injection
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
Nucleicritical
WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir
Nucleicritical
WordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL Injection
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection
48RIESGO
abrir
Nucleimedium
Quick Event Manager < 9.7.5 - Cross-Site Scripting
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability
28RIESGO
abrir
Nucleicritical
Jms Blog - SQL Injection
PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
55RIESGO
abrir
Nucleihigh
Appwrite <=1.2.1 - Server-Side Request Forgery
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favic
48RIESGO
abrir
Nucleimedium
Request-Baskets <= 1.2.1 - Server Side Request Forgery
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
Nucleihigh
GDidees CMS v3.9.1 - Arbitrary File Download
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RIESGO
abrir
Nucleimedium
OpenCATS - Open Redirect
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET pa
28RIESGO
abrir
Nucleicritical
MStore API <= 3.9.2 - Authentication Bypass
MStore API <= 3.9.2 - Authentication Bypass
75RIESGO
abrir
Nucleicritical
MStore API <= 3.9.1 - Authentication Bypass
MStore API <= 3.9.1 - Authentication Bypass
43RIESGO
abrir
Nucleicritical
PaperCut - Unauthenticated Remote Code Execution
CVE-2023-27350CRITICALbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
anteriorpágina 123 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.