Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
Referência
CVE-2012-1002
SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2015-2216
SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to exec
23RIESGO
abrir
Referência
CVE-2026-16289
ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
33RIESGO
abrir
Referência
CVE-2015-2090
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 fo
23RIESGO
abrir
Referência
CVE-2015-2090
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 fo
23RIESGO
abrir
Referência
CVE-2014-10013
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to
23RIESGO
abrir
Referência
CVE-2026-16250
Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
23RIESGO
abrir
Referência
CVE-2012-2276
The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote
23RIESGO
abrir
Referência
CVE-2017-18195
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enum
28RIESGO
abrir
Referência
CVE-2009-3975
SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2013-6793
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote a
23RIESGO
abrir
Referência
CVE-2015-4667
Multiple hardcoded credentials in Xsuite 2.x.
28RIESGO
abrir
Referência
CVE-2017-13869
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Referência
CVE-2026-16060
Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File Upload
23RIESGO
abrir
Referência
CVE-2018-10504
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
23RIESGO
abrir
Referência
CVE-2021-43140
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
23RIESGO
abrir
Referência
CVE-2015-4010
Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows rem
23RIESGO
abrir
Referência
Veyon 4.4.1 - 'VeyonService' Unquoted Service Path
CVE-2020-15261HIGHlocalwindows
Unquoted service path vulnerability on Veyon
46RIESGO
abrir
Referência
CVE-2026-16276
Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search
23RIESGO
abrir
Referência
CVE-2019-10846
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw
23RIESGO
abrir
Referência
CVE-2017-15956
ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.
23RIESGO
abrir
Referência
CVE-2016-1793
AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged
23RIESGO
abrir
Referência
CVE-2016-1793
AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged
23RIESGO
abrir
Referência
CVE-2026-16274
Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts
23RIESGO
abrir
Referência
CVE-2026-16057
Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library
23RIESGO
abrir
Referência
CVE-2016-1794
The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attack
23RIESGO
abrir
Referência
CVE-2022-45639
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a cra
41RIESGO
abrir
Referência
CVE-2026-3485
D-Link DIR-868L SSDP Service sub_1BF84 os command injection
48RIESGO
abrir
Referência
CVE-2026-15254
Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode
33RIESGO
abrir
Referência
CVE-2015-2682
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via
28RIESGO
abrir
anteriorpágina 313 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.