Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.666exploits catalogados
32.032CVEs con explotación pública
1932probados en laboratorio
4191 exploits
Nucleicritical
JetBrains TeamCity > 2023.11.3 - Authentication Bypass
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
55RIESGO
abrir
Nucleicritical
Exrick XMall - SQL Injection
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
43RIESGO
abrir
Nucleicritical
Ruijie RG-NBS2009G-P - Improper Authentication
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the syst
48RIESGO
abrir
Nucleimedium
SuperWebMailer 9.31.0.01799 - Cross-Site Scripting
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the comp
28RIESGO
abrir
Nucleicritical
TotoLink Router setMacFilterRules - Command Injection
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param
36RIESGO
abrir
Nucleicritical
TotoLink Router setPortForwardRules - Command Injection
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param
43RIESGO
abrir
Nucleimedium
CrateDB Database - Arbitrary File Read
CrateDB database has an arbitrary file read vulnerability
28RIESGO
abrir
Nucleimedium
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
48RIESGO
abrir
Nucleihigh
MindsDB -DNS Rebinding SSRF Protection Bypass
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
43RIESGO
abrir
Nucleimedium
JumpServer < 3.10.0 - Open Redirect
JumpServer Open Redirect Vulnerability
28RIESGO
abrir
Nucleihigh
Traccar - Unrestricted File Upload
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RIESGO
abrir
Nucleicritical
Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
43RIESGO
abrir
Nucleihigh
Check Point Quantum Gateway - Information Disclosure
CVE-2024-24919HIGHbajo ataqueransomware
Information disclosure
100RIESGO
abrir
Nucleicritical
Unauthenticated Remote Code Execution – Bricks <= 1.9.6
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
Nucleimedium
Liferay Portal - Open Redirect
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 be
28RIESGO
abrir
Nucleicritical
ZenML ZenML Server - Improper Authentication
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because t
58RIESGO
abrir
Nucleihigh
WyreStorm Apollo VX20 - Information Disclosure
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password
75RIESGO
abrir
Nucleihigh
Linksys RE7000 - Command Injection
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter
41RIESGO
abrir
Nucleihigh
GeoServer Demo Request Endpoint - Server Side Request Forgery
GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
36RIESGO
abrir
Nucleicritical
Telesquare TLR-2005KSH - Remote Command Execution
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RIESGO
abrir
Nucleimedium
VvvebJs < 1.7.5 - Arbitrary File Upload
Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute
28RIESGO
abrir
Nucleihigh
MLflow < 2.11.3 - Path Traversal
Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow
41RIESGO
abrir
Nucleimedium
Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting
WordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerability
36RIESGO
abrir
Nucleicritical
Ivanti EPM - Remote Code Execution
CVE-2024-29824CRITICALbajo ataque
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RIESGO
abrir
Nucleicritical
Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RIESGO
abrir
Nucleihigh
GLPI 10.0.10-10.0.14 - SQL Injection
GLPI contains an SQL injection through the saved searches
48RIESGO
abrir
Nucleicritical
Cacti cmd_realtime.php - Command Injection
Cacti command injection in cmd_realtime.php
85RIESGO
abrir
Nucleimedium
WP Go Maps <= 9.0.29 - Cross-Site Scripting
WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability
36RIESGO
abrir
Nucleicritical
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RIESGO
abrir
Nucleicritical
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command Injection
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.