Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.666exploits catalogados
32.032CVEs con explotación pública
1932probados en laboratorio
4191 exploits
Nucleihigh
Pascom CPS - Local File Inclusion
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Pho
23RIESGO
abrir
Nucleimedium
Sourcecodester Car Rental Management System 1.0 - Stored Cross-Site Scripting
Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter
18RIESGO
abrir
Nucleimedium
Vehicle Service Management System - Stored Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Sec
18RIESGO
abrir
Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List
18RIESGO
abrir
Nucleimedium
ehicle Service Management System 1.0 - Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List
18RIESGO
abrir
Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List S
18RIESGO
abrir
Nucleimedium
Vehicle Service Management System 1.0 - Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the
18RIESGO
abrir
Nucleihigh
webp_server_go 0.4.0 - Path Traversal
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi
18RIESGO
abrir
Nucleihigh
Ligeo Archives Ligeo Basics - Server Side Request Forgery
Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacke
18RIESGO
abrir
Nucleihigh
AntD Admin - Sensitive Information Disclosure
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the
18RIESGO
abrir
Nucleimedium
D-Link DIR850 ET850-1.08TRb03 - Open Redirect
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RIESGO
abrir
Nucleihigh
D-Link DAP-1620 - Local File Inclusion
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RIESGO
abrir
Nucleimedium
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RIESGO
abrir
Nucleihigh
Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RIESGO
abrir
Nucleihigh
Telesquare TLR-2855KS6 - Arbitrary File Creation
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
43RIESGO
abrir
Nucleicritical
WordPress BadgeOS <=3.7.0 - SQL Injection
BadgeOS <= 3.7.0 - Unauthenticated SQLi
23RIESGO
abrir
Nucleihigh
Webmin <1.990 - Improper Access Control
Improper Access Control to Remote Code Execution in webmin/webmin
78RIESGO
abrir
Nucleicritical
WordPress WP Video Gallery <=1.7.1 - SQL Injection
WP Video Gallery <= 1.7.1 - Unauthenticated SQLi
18RIESGO
abrir
Nucleicritical
WordPress Best Books <=2.6.3 - SQL Injection
Bestbooks <= 2.6.3 - Unauthenticated SQLi
18RIESGO
abrir
Nucleicritical
SpeakOut Email Petitions < 2.14.15.1 - SQL Injection
SpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLi
18RIESGO
abrir
Nucleimedium
UpdraftPlus < 1.22.9 - Cross-Site Scripting
UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleicritical
WordPress ARPrice <3.6.1 - SQL Injection
ARPrice Lite < 3.6.1 - Unauthenticated SQLi
23RIESGO
abrir
Nucleimedium
nitely/spirit 0.12.3 - Open Redirect
Multiple Open Redirect in nitely/spirit
28RIESGO
abrir
Nucleimedium
Gogs <0.12.5 - Server-Side Request Forgery
Server-Side Request Forgery (SSRF) in gogs/gogs
28RIESGO
abrir
Nucleimedium
WordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site Scripting
Gmedia Photo Gallery < 1.20.0 - Admin+ Stored Cross-Site Scripting
18RIESGO
abrir
Nucleimedium
Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting
Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleicritical
Member Hero <=1.0.9 - Remote Code Execution
Member Hero <= 1.0.9 - Unauthenticated RCE
18RIESGO
abrir
Nucleimedium
Header Footer Code Manager < 1.1.24 - Cross-Site Scripting
Header Footer Code Manager < 1.1.24 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleimedium
Microweber < 1.2.12 - Stored Cross-Site Scripting
Cross-site Scripting (XSS) - Stored in microweber/microweber
28RIESGO
abrir
Nucleicritical
WordPress Order Listener for WooCommerce <3.2.2 - SQL Injection
Order Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi
18RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.