Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
4350 exploits
Nucleihigh
Gogs 0.5.5 - 0.12.2 - Remote Code Execution
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privile
40RIESGO
abrir
Nucleimedium
D-Link DIR-816L 2.x - Cross-Site Scripting
An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no outp
18RIESGO
abrir
Nucleicritical
Tiki Wiki CMS GroupWare - Authentication Bypass
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
23RIESGO
abrir
Nucleicritical
Mida eFramework <=2.9.0 - Remote Command Execution
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RIESGO
abrir
Nucleihigh
Cisco Unified IP Conference Station 7937G - Denial-of-Service
A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the de
40RIESGO
abrir
Nucleicritical
74cms - ajax_street.php 'key' SQL Injection
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
18RIESGO
abrir
Nucleimedium
b2evolution CMS <6.11.6 - Open Redirect
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redi
23RIESGO
abrir
Nucleimedium
OPNsense <=20.1.5 - Open Redirect
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not fil
18RIESGO
abrir
Nucleimedium
Aryanic HighMail (High CMS) - Cross-Site Scripting
Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers
18RIESGO
abrir
Nucleihigh
Kyocera Printer d-COPIA253MF - Directory Traversal
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnera
30RIESGO
abrir
Nucleimedium
Monstra CMS 3.0.4 - Cross-Site Scripting
Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.
18RIESGO
abrir
Nucleimedium
XXL-JOB v2.2.0 — Stored Cross Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web scr
18RIESGO
abrir
Nucleihigh
Joomla! Component GMapFP 3.5 - Arbitrary File Upload
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating
50RIESGO
abrir
Nucleicritical
Import XML & RSS Feeds WordPress Plugin <= 2.0.1 Server-Side Request Forgery
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the
23RIESGO
abrir
Nucleicritical
WordPress wpDiscuz <=7.0.4 - Remote Code Execution
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir
Nucleimedium
Mara CMS 7.5 - Cross-Site Scripting
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
43RIESGO
abrir
Nucleihigh
INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion
INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgi
18RIESGO
abrir
Nucleihigh
WordPress Plugin File Manager (wp-file-manager) Backup Disclosure
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htacce
23RIESGO
abrir
Nucleicritical
Mongo-Express - Remote Code Execution
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this m
40RIESGO
abrir
Nucleimedium
EpiServer Find <13.2.7 - Open Redirect
An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted website
18RIESGO
abrir
Nucleihigh
NexusDB <4.50.23 - Local File Inclusion
NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
23RIESGO
abrir
Nucleihigh
D-Link DSL 2888a - Authentication Bypass/Remote Command Execution
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attac
18RIESGO
abrir
Nucleicritical
WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection
48RIESGO
abrir
Nucleimedium
OX Appsuite - Cross-Site Scripting
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
18RIESGO
abrir
Nucleicritical
OsTicket < 1.14.3 - Server Side Request Forgery
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RIESGO
abrir
Nucleimedium
Quixplorer <=2.4.1 - Cross-Site Scripting
Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied
28RIESGO
abrir
Nucleimedium
Cute Editor for ASP.NET 6.4 - Cross-Site Scripting
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user
18RIESGO
abrir
Nucleimedium
QCube Cross-Site-Scripting
A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQ
18RIESGO
abrir
Nucleihigh
PHP-Fusion 9.03.50 - Remote Code Execution
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RIESGO
abrir
Nucleihigh
D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure
CVE-2020-25078HIGHbajo ataque
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.