Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
4201 exploits
Nucleihigh
Apache Flink - Local File Inclusion
CVE-2020-17519CRITICALbajo ataque
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
Nucleihigh
Apache Airflow <1.10.14 - Authentication Bypass
Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a maliciou
23RIESGO
abrir
Nucleicritical
Apache Struts 2.0.0-2.5.25 - Remote Code Execution
CVE-2020-17530CRITICALbajo ataque
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
Nucleimedium
Z-Blog <=1.5.2 - Open Redirect
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect"
18RIESGO
abrir
Nucleimedium
Jeesns 1.4.2 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts o
18RIESGO
abrir
Nucleimedium
Jeesns 1.4.2 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to ex
18RIESGO
abrir
Nucleimedium
Jeesns 1.4.2 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to e
18RIESGO
abrir
Nucleihigh
FHEM 6.0 - Local File Inclusion
Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a fil
23RIESGO
abrir
Nucleimedium
Vtiger CRM v7.2.0 - Directory Listing
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directori
18RIESGO
abrir
Nucleimedium
Apache OFBiz <=16.11.07 - Cross-Site Scripting
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
40RIESGO
abrir
Nucleimedium
qdPM 9.1 - Cross-site Scripting
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
18RIESGO
abrir
Nucleihigh
Apache Kylin 3.0.1 - Command Injection Vulnerability
CVE-2020-1956HIGHbajo ataque
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the
100RIESGO
abrir
Nucleicritical
Gridx 1.3 - Remote Code Execution
Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attack
23RIESGO
abrir
Nucleimedium
ZZcms - Cross-Site Scripting
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
18RIESGO
abrir
Nucleicritical
WeiPHP 5.0 - SQL Injection
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
18RIESGO
abrir
Nucleihigh
Palo Alto Networks PAN-OS Web Interface - Cross Site-Scripting
PAN-OS: Reflected Cross-Site Scripting (XSS) vulnerability in management web interface
41RIESGO
abrir
Nucleicritical
WordPress File Manager Plugin - Remote Code Execution
CVE-2020-25213CRITICALbajo ataque
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
Nucleicritical
Sophos UTM Preauth - Remote Code Execution
CVE-2020-25223CRITICALbajo ataque
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RIESGO
abrir
Nucleimedium
Xinuo Openserver 5/6 - Cross-Site scripting
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at
38RIESGO
abrir
Nucleicritical
D-Link DNS-320 - Unauthenticated Remote Code Execution
CVE-2020-25506CRITICALbajo ataque
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead
95RIESGO
abrir
Nucleicritical
Oracle WebLogic Server - Remote Code Execution
CVE-2020-2551CRITICALbajo ataque
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
Nucleihigh
ThinkAdmin 6 - Local File Inclusion
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RIESGO
abrir
Nucleihigh
Commvault CommCell - Local File Inclusion
In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, D
18RIESGO
abrir
Nucleimedium
HashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site Scripting
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scriptin
18RIESGO
abrir
Nucleihigh
Cisco SD-WAN vManage Software - Local File Inclusion
Cisco SD-WAN vManage Directory Traversal Vulnerability
41RIESGO
abrir
Nucleimedium
Event Espresso Core-Reg 4.10.7.p - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/
18RIESGO
abrir
Nucleicritical
Alerta < 8.1.0 - Authentication Bypass
LDAP authentication bypass in Alerta
55RIESGO
abrir
Nucleihigh
XStream <1.4.14 - Remote Code Execution
Remote Code Execution in XStream
58RIESGO
abrir
Nucleihigh
PrestaShop Product Comments <4.2.0 - SQL Injection
Blind SQL injection during the CommentGrade process
33RIESGO
abrir
Nucleihigh
XStream <1.4.15 - Server-Side Request Forgery
Server-Side Forgery Request can be activated unmarshalling with XStream
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.