Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.901exploits catalogados
32.161CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleihigh
aiohttp - Directory Traversal
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
Nucleimedium
Avada < 7.11.7 - Information Disclosure
Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing
33RIESGO
abrir
Nucleicritical
Rejetto HTTP File Server - Template injection
CVE-2024-23692CRITICALbajo ataque
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
Nucleicritical
Progress Kemp Flowmon - Command Injection
Flowmon Unauthenticated Command Injection Vulnerability
85RIESGO
abrir
Nucleicritical
JetBrains TeamCity > 2023.11.3 - Authentication Bypass
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
55RIESGO
abrir
Nucleicritical
Exrick XMall - SQL Injection
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
43RIESGO
abrir
Nucleicritical
Ruijie RG-NBS2009G-P - Improper Authentication
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the syst
48RIESGO
abrir
Nucleimedium
SuperWebMailer 9.31.0.01799 - Cross-Site Scripting
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the comp
28RIESGO
abrir
Nucleicritical
TotoLink Router setMacFilterRules - Command Injection
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param
36RIESGO
abrir
Nucleicritical
TotoLink Router setPortForwardRules - Command Injection
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param
43RIESGO
abrir
Nucleimedium
CrateDB Database - Arbitrary File Read
CrateDB database has an arbitrary file read vulnerability
28RIESGO
abrir
Nucleimedium
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
48RIESGO
abrir
Nucleihigh
MindsDB -DNS Rebinding SSRF Protection Bypass
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
43RIESGO
abrir
Nucleimedium
JumpServer < 3.10.0 - Open Redirect
JumpServer Open Redirect Vulnerability
28RIESGO
abrir
Nucleihigh
Traccar - Unrestricted File Upload
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RIESGO
abrir
Nucleicritical
Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
43RIESGO
abrir
Nucleihigh
Check Point Quantum Gateway - Information Disclosure
CVE-2024-24919HIGHbajo ataqueransomware
Information disclosure
100RIESGO
abrir
Nucleicritical
Unauthenticated Remote Code Execution – Bricks <= 1.9.6
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
Nucleimedium
Liferay Portal - Open Redirect
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 be
28RIESGO
abrir
Nucleicritical
ZenML ZenML Server - Improper Authentication
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because t
58RIESGO
abrir
Nucleihigh
WyreStorm Apollo VX20 - Information Disclosure
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password
75RIESGO
abrir
Nucleihigh
Linksys RE7000 - Command Injection
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter
41RIESGO
abrir
Nucleimedium
Fujian Kelixin Communication - Command Injection
Fujian Kelixin Communication Command and Dispatch Platform pwd_update.php sql injection
28RIESGO
abrir
Nucleihigh
Avid NEXIS Agent - Arbitrary File Read
Authenticated Arbitrary File Read affecting Avid NEXIS
36RIESGO
abrir
Nucleihigh
ReCrystallize Server - Authentication Bypass
ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind
48RIESGO
abrir
Nucleicritical
InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir
Nucleihigh
SOPlanning - Remote Code Execution
Remote Code Execution through File Upload in SOPlanning before 1.52.02
43RIESGO
abrir
Nucleicritical
Mura/Masa CMS - SQL Injection
MasaCMS SQL Injection vulnerability
85RIESGO
abrir
Nucleicritical
Change Detection - Server Side Template Injection
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RIESGO
abrir
Nucleicritical
WP-Recall <= 16.26.5 - SQL Injection
WordPress WP-Recall plugin <= 16.26.5 - SQL Injection vulnerability
43RIESGO
abrir
anteriorpágina 124 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.