Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
4193 exploits
Nucleimedium
Companion Sitemap Generator < 4.5.3 - Cross-Site Scripting
Companion Sitemap Generator < 4.5.3 - Reflected XSS
18RIESGO
abrir
Nucleimedium
Ninja Forms < 3.6.22 - Cross-Site Scripting
Ninja Forms < 3.6.22 - Reflected XSS
28RIESGO
abrir
Nucleimedium
Phpmyfaq v3.1.11 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
36RIESGO
abrir
Nucleimedium
Tablesome < 1.0.9 - Cross-Site Scripting
Tablesome < 1.0.9 - Reflected XSS
28RIESGO
abrir
Nucleicritical
Sidekiq < 7.0.8 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in sidekiq/sidekiq
36RIESGO
abrir
Nucleimedium
Login Configurator <=2.1 - Cross-Site Scripting
Login Configurator <= 2.1 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleicritical
Cisco VPN Routers - Unauthenticated Arbitrary File Upload
Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Arbitrary File Upload Vulnerability
70RIESGO
abrir
Nucleimedium
Pretty Url <= 1.5.4 - Cross-Site Scripting
Pretty Url <= 1.5.4 - Admin+ Stored XSS in plugin settings
28RIESGO
abrir
Nucleicritical
Cisco IOS XE Web UI - Command Injection
CVE-2023-20198CRITICALbajo ataque
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
Nucleimedium
Custom 404 Pro < 3.7.3 - Cross-Site Scripting
Custom 404 Pro < 3.7.3 - Reflected Cross-Site Scripting
28RIESGO
abrir
Nucleimedium
DedeCMS 5.7.87 - Directory Traversal
DedeCMS select_templets.php path traversal
28RIESGO
abrir
Nucleicritical
VMware Aria Operations for Logs - Unauthenticated Remote Code Execution
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with netwo
65RIESGO
abrir
Nucleicritical
VMware VRealize Network Insight - Remote Code Execution
CVE-2023-20887CRITICALbajo ataque
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RIESGO
abrir
Nucleihigh
VMware Aria Operations for Networks - Remote Code Execution
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network acc
58RIESGO
abrir
Nucleihigh
VMware Aria Operations for Networks - Code Injection Information Disclosure Vulnerability
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to
58RIESGO
abrir
Nucleimedium
Image Optimizer by 10web < 1.0.26 - Cross-Site Scripting
Image Optimizer by 10web < 1.0.27 - Reflected Cross-Site Scripting
18RIESGO
abrir
Nucleicritical
Purchase Order Management v1.0 - SQL Injection
SourceCodester Purchase Order Management System GET Parameter view_details.php sql injection
28RIESGO
abrir
Nucleimedium
Aajoda Testimonials < 2.2.2 - Cross-Site Scripting
Aajoda Testimonials < 2.2.2 - Admin+ Stored XSS
18RIESGO
abrir
Nucleihigh
Oracle Peoplesoft - Unauthenticated File Read
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported vers
58RIESGO
abrir
Nucleimedium
Adobe Connect < 12.1.5 - Local File Disclosure
Adobe Connect Improper Access Control Security feature bypass
70RIESGO
abrir
Nucleimedium
Seo By 10Web < 1.2.7 - Cross-Site Scripting
Seo By 10Web < 1.2.7 - Admin+ Stored XSS
28RIESGO
abrir
Nucleicritical
Modoboa < 2.1.0 - Improper Authorization
Improper Authorization in modoboa/modoboa
55RIESGO
abrir
Nucleimedium
Web2py URL - Open Redirect
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirec
28RIESGO
abrir
Nucleicritical
KubePi JwtSigKey - Admin Authentication Bypass
KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT token
55RIESGO
abrir
Nucleihigh
KubePi <= v1.6.4 LoginLogsSearch - Unauthorized Access
KubePi is vulnerable to missing authorization
36RIESGO
abrir
Nucleicritical
KubeOperator Foreground `kubeconfig` - File Download
KubeOperator is vulnerable to unauthorized access to system API
48RIESGO
abrir
Nucleicritical
Atlassian Confluence - Privilege Escalation
CVE-2023-22515CRITICALbajo ataqueransomware
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
Nucleicritical
Atlassian Confluence Server - Improper Authorization
CVE-2023-22518CRITICALbajo ataqueransomware
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir
Nucleilow
Directorist < 7.5.4 - Local File Inclusion
Directorist < 7.5.4 - Admin+ LFI
23RIESGO
abrir
Nucleicritical
Atlassian Confluence - Remote Code Execution
CVE-2023-22527CRITICALbajo ataqueransomware
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.