Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
4193 exploits
Nucleimedium
Base64 Encoder/Decoder <= 0.9.2 - Cross-Site Scripting
Base64 Encoder/Decoder <= 0.9.2 - Reflected XSS
28RIESGO
abrir
Nucleihigh
TurboMeeting - Post-Authentication Command Injection
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allow
36RIESGO
abrir
Nucleicritical
TurboMeeting - Boolean-based SQL Injection
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x all
55RIESGO
abrir
Nucleimedium
CodiMD <2.5.4 - Insecure Filename Randomization
CodiMD - Missing Image Access Controls and Unauthorized Image Access
28RIESGO
abrir
Nucleihigh
Apache HTTPd Windows UNC - Server-Side Request Forgery
Apache HTTP Server on WIndows UNC SSRF
48RIESGO
abrir
Nucleihigh
Apache HTTP Server - ACL Bypass
Apache HTTP Server proxy encoding problem
41RIESGO
abrir
Nucleicritical
Sonicwall - Pre-Authentication Arbitrary File Read
CVE-2024-38475CRITICALbajo ataque
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RIESGO
abrir
Nucleihigh
Mlflow < 2.11.0 - Path Traversal
Path Traversal Bypass in mlflow/mlflow
48RIESGO
abrir
Nucleimedium
Uniview NVR301-04S2-P4 - Cross-Site Scripting
Uniview NVR301-04S2-P4 Cross-site Scripting
28RIESGO
abrir
Nucleihigh
NextChat - Server-Side Request Forgery
NextChat Server-Side Request Forgery (SSRF)
36RIESGO
abrir
Nucleihigh
Ivanti Avalanche SmartDeviceServer - XML External Entity
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on t
58RIESGO
abrir
Nucleicritical
FormLift for Infusionsoft Web Forms <= 7.5.17 - SQL Injection
WordPress formlift plugin <= 7.5.17 - Unauthenticated Blind SQL Injection vulnerability
43RIESGO
abrir
Nucleihigh
WebMvc.fn/WebFlux.fn - Path Traversal
CVE-2024-38816: Path traversal vulnerability in functional web frameworks
61RIESGO
abrir
Nucleihigh
Spring Framework Path Traversal in Functional Web Frameworks
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to pa
48RIESGO
abrir
Nucleicritical
Apache OFBiz - Improper Authorization & Remote Code Execution
CVE-2024-38856HIGHbajo ataque
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
Nucleicritical
Dokan Pro <= 3.10.3 - SQL Injection
Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection
75RIESGO
abrir
Nucleihigh
EfroTech Timetrax v8.3 - Sql Injection
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t
63RIESGO
abrir
Nucleihigh
WordPress Custom 404 Pro <= 3.11.1 - Reflected XSS
WordPress Custom 404 Pro plugin <= 3.11.1 - Reflected Cross Site Scripting (XSS) vulnerability
36RIESGO
abrir
Nucleihigh
Rocket.Chat - Server-Side Request Forgery (SSRF)
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RIESGO
abrir
Nucleimedium
Apache Superset < 4.0.2 - SQL Injection
Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions
28RIESGO
abrir
Nucleihigh
Solara <1.35.1 - Local File Inclusion
Local File Inclusion in Solara
36RIESGO
abrir
Nucleicritical
1Panel SQL Injection - Authenticated
a sqlinjection in 1Panel
48RIESGO
abrir
Nucleicritical
FOG Project < 1.5.10.34 - Remote Command Execution
FOG has a command injection in /fog/management/export.php?filename=
68RIESGO
abrir
Nucleihigh
Bazarr < 1.4.3 - Arbitrary File Read
An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory
36RIESGO
abrir
Nucleicritical
CrushFTP VFS - Sandbox Escape LFR
CVE-2024-4040CRITICALbajo ataque
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
Nucleicritical
Devika v1 - Path Traversal
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RIESGO
abrir
Nucleicritical
Veeam Backup & Replication - Unauthenticated
CVE-2024-40711CRITICALbajo ataqueransomware
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RIESGO
abrir
Nucleicritical
Apache CloudStack - SAML Signature Exclusion
Apache CloudStack: SAML Signature Exclusion
41RIESGO
abrir
Nucleihigh
Cluster Control CMON API - Directory Traversal
Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and
36RIESGO
abrir
Nucleihigh
OpenAM<=15.0.3 FreeMarker - Template Injection
OpenAM FreeMarker template injection
36RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.