Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleicritical
Dokan Pro <= 3.10.3 - SQL Injection
Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection
75RIESGO
abrir
Nucleihigh
EfroTech Timetrax v8.3 - Sql Injection
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t
63RIESGO
abrir
Nucleihigh
WordPress Custom 404 Pro <= 3.11.1 - Reflected XSS
WordPress Custom 404 Pro plugin <= 3.11.1 - Reflected Cross Site Scripting (XSS) vulnerability
36RIESGO
abrir
Nucleihigh
Rocket.Chat - Server-Side Request Forgery (SSRF)
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RIESGO
abrir
Nucleimedium
Apache Superset < 4.0.2 - SQL Injection
Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions
28RIESGO
abrir
Nucleihigh
Solara <1.35.1 - Local File Inclusion
Local File Inclusion in Solara
36RIESGO
abrir
Nucleicritical
1Panel SQL Injection - Authenticated
a sqlinjection in 1Panel
48RIESGO
abrir
Nucleicritical
FOG Project < 1.5.10.34 - Remote Command Execution
FOG has a command injection in /fog/management/export.php?filename=
68RIESGO
abrir
Nucleihigh
Bazarr < 1.4.3 - Arbitrary File Read
An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory
36RIESGO
abrir
Nucleicritical
CrushFTP VFS - Sandbox Escape LFR
CVE-2024-4040CRITICALbajo ataque
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
Nucleicritical
Devika v1 - Path Traversal
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RIESGO
abrir
Nucleicritical
Veeam Backup & Replication - Unauthenticated
CVE-2024-40711CRITICALbajo ataqueransomware
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RIESGO
abrir
Nucleicritical
Apache CloudStack - SAML Signature Exclusion
Apache CloudStack: SAML Signature Exclusion
41RIESGO
abrir
Nucleihigh
Cluster Control CMON API - Directory Traversal
Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and
36RIESGO
abrir
Nucleihigh
OpenAM<=15.0.3 FreeMarker - Template Injection
OpenAM FreeMarker template injection
36RIESGO
abrir
Nucleihigh
Mitel MiCollab - Authentication Bypass
CVE-2024-41713CRITICALbajo ataqueransomware
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
Nucleimedium
The Events Calendar < 6.4.0.1 - Cross-site Scripting
The Events Calendar < 6.4.0.1 - Reflected XSS
63RIESGO
abrir
Nucleimedium
Twisted - Open Redirect & XSS
HTML injection in HTTP redirect body
28RIESGO
abrir
Nucleimedium
Open Redirect in Login Redirect - MobSF
Mobile Security Framework (MobSF) has an Open Redirect in Login Redirect
28RIESGO
abrir
Nucleicritical
Roundcube Webmail - Cross-Site Scripting
CVE-2024-42009CRITICALbajo ataque
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
Nucleihigh
Apache HertzBeat < 1.6.0 - SnakeYAML Deserialization Remote Code Execution
Apache HertzBeat: RCE by snakeYaml deser load malicious xml
36RIESGO
abrir
Nucleimedium
BlueNet Technology Clinical Browsing System 1.2.1 - Sql Injection
BlueNet Technology Clinical Browsing System deleteStudy.php sql injection
33RIESGO
abrir
Nucleicritical
Angular-Base64-Upload - Remote Code Execution
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RIESGO
abrir
Nucleimedium
AcuToWeb server/10.5.0.7577c8b - Cross-Site Scripting
Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary cod
28RIESGO
abrir
Nucleicritical
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via Hash
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RIESGO
abrir
Nucleicritical
Cost Calculator Builder <= 3.2.15 - SQL Injection
WordPress Cost Calculator Builder plugin <= 3.2.15 - SQL Injection vulnerability
43RIESGO
abrir
Nucleicritical
BerqWP <= 1.7.6 - Arbitrary File Upload
WordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability
63RIESGO
abrir
Nucleihigh
LoLLMS WebUI < 9.8 - Path Traversal
Path Traversal in parisneo/lollms-webui
48RIESGO
abrir
Nucleihigh
Gradio - Server-Side Request Forgery
Server-Side Request Forgery (SSRF) in gradio-app/gradio
48RIESGO
abrir
Nucleimedium
Contest Gallery - Broken Access Control
WordPress Contest Gallery plugin <= 23.1.2 - Unauthenticated Comment UserID And IP address Disclosure vulnerability
28RIESGO
abrir
anteriorpágina 127 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.