Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
4217 exploits
Nucleimedium
MooDating 1.2 - Cross-Site Scripting
mooSocial mooDating URL ajax_invite cross site scripting
43RIESGO
abrir
Nucleimedium
MooDating 1.2 - Cross-Site Scripting
mooSocial mooDating URL pages cross site scripting
43RIESGO
abrir
Nucleimedium
MooDating 1.2 - Cross-Site scripting
mooSocial mooDating URL users cross site scripting
43RIESGO
abrir
Nucleimedium
MooDating 1.2 - Cross-site scripting
mooSocial mooDating URL view cross site scripting
43RIESGO
abrir
Nucleimedium
mooDating 1.2 - Cross-site scripting
mooSocial mooDating URL find-a-match cross site scripting
43RIESGO
abrir
Nucleimedium
CopyParty v1.8.6 - Cross Site Scripting
copyparty vulnerable to reflected cross-site scripting via k304 parameter
48RIESGO
abrir
Nucleicritical
Metabase < 0.46.6.1 - Remote Code Execution
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
Nucleimedium
PHP Login System 2.0.1 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to ex
18RIESGO
abrir
Nucleihigh
openSIS v9.0 - Path Traversal
The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a direc
18RIESGO
abrir
Nucleihigh
ZKTeco BioTime v8.5.5 - Path Traversal
CVE-2023-38950HIGHbajo ataque
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbit
100RIESGO
abrir
Nucleihigh
ZKTeco BioTime <= 9.0.1 - Privilege Escalation
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due
36RIESGO
abrir
Nucleimedium
Academy LMS 6.0 - Cross-Site Scripting
Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
18RIESGO
abrir
Nucleicritical
Jeecg-Boot v3.5.1 - SQL Injection
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeD
40RIESGO
abrir
Nucleimedium
OPNsense - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition
18RIESGO
abrir
Nucleicritical
OPNsense - Cross-Site Scripting to RCE
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 al
18RIESGO
abrir
Nucleihigh
FileMage Gateway - Directory Traversal
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
43RIESGO
abrir
Nucleihigh
rConfig 3.9.4 - Server-Side Request Forgery
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Fun
18RIESGO
abrir
Nucleihigh
rConfig 3.9.4 - Server-Side Request Forgery
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Fun
18RIESGO
abrir
Nucleihigh
rConfig 3.9.4 - Server-Side Request Forgery
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPa
18RIESGO
abrir
Nucleihigh
Emlog 2.1.9 - SQL Injection
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
18RIESGO
abrir
Nucleihigh
Aria2 WebUI - Path traversal
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
18RIESGO
abrir
Nucleicritical
PaperCut < 22.1.3 - Path Traversal
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete
85RIESGO
abrir
Nucleimedium
Blog2Social < 7.2.1 - Cross-Site Scripting
Blog2Social < 7.2.1 - Reflected XSS
28RIESGO
abrir
Nucleicritical
Cacti 1.2.24 - SQL Injection
Unauthenticated SQL Injection in graph_view.php in Cacti
85RIESGO
abrir
Nucleicritical
ECTouch v2 - SQL Injection
ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\inse
18RIESGO
abrir
Nucleimedium
IceWarp Email Client - Cross Site Scripting
Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitra
18RIESGO
abrir
Nucleicritical
Anyscale Ray 2.6.3 and 2.8.0 - Server-Side Request Forgery
Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant becau
55RIESGO
abrir
Nucleicritical
Nagios XI < 5.11.3 - SQL Injection
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
50RIESGO
abrir
Nucleihigh
XWiki < 4.10.15 - Information Disclosure
XWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest service
58RIESGO
abrir
Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.
43RIESGO
abrir
anteriorpágina 133 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.