Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
22.175 exploits
ReferênciaVexDay Proof
Mambo Module Calendar (Agenda) 1.5.5 - Remote File Inclusion
CVE-2007-2049webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote at
23RIESGO
abrir
ReferênciaVexDay Proof
RicarGBooK 1.2.1 - 'lang' Local File Inclusion
CVE-2007-2050webappsphp
Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and exe
23RIESGO
abrir
Referência
CVE-2021-31207
CVE-2021-31207MEDIUMbajo ataqueransomware
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RIESGO
abrir
Referência
CVE-2025-34103
WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
63RIESGO
abrir
Referência
CVE-2026-6381
WP Maps < 4.9.3 - Subscriber+ Local File Inclusion
41RIESGO
abrir
Referência
CVE-2026-6379
WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter
41RIESGO
abrir
ReferênciaVexDay Proof
openMairie 1.10 - '/scr/soustab.php' Local File Inclusion
CVE-2007-2069webappsphp
Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include a
23RIESGO
abrir
Referência
CVE-2009-3808
MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute
23RIESGO
abrir
Referência
CVE-2009-3835
SQL injection vulnerability in the JShop (com_jshop) component for Joomla! allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2009-3857
Buffer overflow in Softonic International SciTE 1.72 allows user-assisted remote attackers to cause a denial of service
23RIESGO
abrir
Referência
CVE-2009-3863
Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause
23RIESGO
abrir
Referência
CVE-2022-47966
CVE-2022-47966CRITICALbajo ataqueransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
Referência
CVE-2022-47966
CVE-2022-47966CRITICALbajo ataqueransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
Referência
CVE-2022-47966
CVE-2022-47966CRITICALbajo ataqueransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
Referência
CVE-2015-2996
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
Referência
CVE-2026-8759
xiandafu beetl SpELFunction SpELFunction.java expression language injection
33RIESGO
abrir
Referência
CVE-2026-8758
Metasoft 美特软件 MetaCRM upload3.jsp unrestricted upload
33RIESGO
abrir
Referência
CVE-2021-38647
CVE-2021-38647CRITICALbajo ataqueransomware
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2015-3036
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RIESGO
abrir
Referência
CVE-2015-3036
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RIESGO
abrir
Referência
CVE-2009-4140
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer
60RIESGO
abrir
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RIESGO
abrir
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RIESGO
abrir
Referência
CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
Referência
CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
Referência
CVE-2017-8687
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Referência
CVE-2022-0543
CVE-2022-0543CRITICALbajo ataque
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
Referência
CVE-2015-3083
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
35RIESGO
abrir
Referência
CVE-2015-3106
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows
35RIESGO
abrir
Referência
CVE-2015-3245
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir
anteriorpágina 402 / 740siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.