Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
4201 exploits
Nucleimedium
SAP Knowledge Warehouse <=7.5.0 - Cross-Site Scripting
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage
43RIESGO
abrir
Nucleicritical
Visual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command Injection
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RIESGO
abrir
Nucleihigh
KONGA 0.14.9 - Privilege Escalation
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to pri
23RIESGO
abrir
Nucleicritical
Sitecore Experience Platform Pre-Auth RCE
CVE-2021-42237CRITICALbajo ataqueransomware
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RIESGO
abrir
Nucleicritical
BillQuick Web Suite SQL Injection
CVE-2021-42258CRITICALbajo ataqueransomware
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution
95RIESGO
abrir
Nucleihigh
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Arbitrary Post Deletion
WP DSGVO Tools (GDPR) <= 3.1.23 Unauthenticated Arbitrary Post Deletion
36RIESGO
abrir
Nucleimedium
Thinfinity VirtualUI User Enumeration
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RIESGO
abrir
Nucleihigh
Oliver 5 Library Server <8.00.008.053 - Local File Inclusion
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet functio
18RIESGO
abrir
Nucleihigh
HD-Network Realtime Monitoring System 2.0 - Local File Inclusion
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RIESGO
abrir
Nucleicritical
Apache Log4j2 - Remote Code Injection
CVE-2021-45046CRITICALbajo ataqueransomware
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
Nucleicritical
Thinfinity Iframe Injection
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RIESGO
abrir
Nucleicritical
Apache APISIX Dashboard <2.10.1 - API Unauthorized Access
security vulnerability on unauthorized access.
40RIESGO
abrir
Nucleimedium
Gitea < 1.4.3 - Open Redirect
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
18RIESGO
abrir
Nucleimedium
AppCMS - Cross-Site Scripting
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
18RIESGO
abrir
Nucleicritical
D-Link - Remote Command Execution
CVE-2021-45382CRITICALbajo ataque
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L
95RIESGO
abrir
Nucleicritical
Emerson Dixell XWEB-500 - Arbitrary File Write
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /
23RIESGO
abrir
Nucleimedium
Reprise License Manager 14.2 - Cross-Site Scripting
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_proce
18RIESGO
abrir
Nucleicritical
Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Upload
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RIESGO
abrir
Nucleicritical
Control Web Panel (CWP) - File Inclusion
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to c
65RIESGO
abrir
Nucleihigh
Slims9 Bulian 9.4.2 - SQL Injection
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
18RIESGO
abrir
Nucleimedium
osTicket 1.15.x - SQL Injection
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticate
18RIESGO
abrir
Nucleicritical
Pascom CPS Server-Side Request Forgery
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend To
23RIESGO
abrir
Nucleihigh
Pascom CPS - Local File Inclusion
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Pho
23RIESGO
abrir
Nucleimedium
Sourcecodester Car Rental Management System 1.0 - Stored Cross-Site Scripting
Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter
18RIESGO
abrir
Nucleimedium
Vehicle Service Management System - Stored Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Sec
18RIESGO
abrir
Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List
18RIESGO
abrir
Nucleimedium
ehicle Service Management System 1.0 - Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List
18RIESGO
abrir
Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List S
18RIESGO
abrir
Nucleimedium
Vehicle Service Management System 1.0 - Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the
18RIESGO
abrir
Nucleihigh
webp_server_go 0.4.0 - Path Traversal
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi
18RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.