Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
22.175 exploits
Referência
CVE-2010-2459
SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2017-1000353
CVE-2017-1000353CRITICALbajo ataque
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir
Referência
CVE-2017-1000353
CVE-2017-1000353CRITICALbajo ataque
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir
Referência
CVE-2026-8275
bettercap zerogod IPP Service zerogod_ipp_primitives.go ippReadChunkedBody integer coercion
33RIESGO
abrir
Referência
CVE-2018-10828
An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and wri
23RIESGO
abrir
Referência
CVE-2017-1000366
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causin
23RIESGO
abrir
Referência
CVE-2016-1583
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to ga
23RIESGO
abrir
Referência
CVE-2016-1583
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to ga
23RIESGO
abrir
Referência
CVE-2013-10070
PHP-Charts v1.0 PHP Code Execution
63RIESGO
abrir
Referência
CVE-2013-10070
PHP-Charts v1.0 PHP Code Execution
63RIESGO
abrir
Referência
CVE-2013-10070
PHP-Charts v1.0 PHP Code Execution
63RIESGO
abrir
ReferênciaVexDay Proof
Softbiz Jobs & Recruitment - SQL Injection
CVE-2007-5316webappsphp
SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2012-10038
Auxilium RateMyPet Arbitrary File Upload RCE
63RIESGO
abrir
Referência
CVE-2025-34089
Remote for Mac Unauthenticated Remote Code Execution via AppleScript Injection
63RIESGO
abrir
Referência
CVE-2025-34089
Remote for Mac Unauthenticated Remote Code Execution via AppleScript Injection
63RIESGO
abrir
Referência
CVE-2012-10052
EGallery 1.2 Arbitrary PHP File Upload
63RIESGO
abrir
Referência
CVE-2012-10052
EGallery 1.2 Arbitrary PHP File Upload
63RIESGO
abrir
Referência
CVE-2012-10052
EGallery 1.2 Arbitrary PHP File Upload
63RIESGO
abrir
Referência
CVE-2025-34150
Shenzhen Aitemi M300 Wi-Fi Repeater PPPoE Username Command Injection
48RIESGO
abrir
ReferênciaVexDay Proof
mail2forum phpBB Mod 1.2 - 'm2f_root_path' Remote File Inclusion
CVE-2006-3735webappsphp
Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attacke
23RIESGO
abrir
Referência
CVE-2016-8972
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the
23RIESGO
abrir
Referência
CVE-2010-2464
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla!
23RIESGO
abrir
ReferênciaVexDay Proof
blogme 3.0 - Cross-Site Scripting / Authentication Bypass
CVE-2006-5976webappsasp
Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2012-2585
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to injec
23RIESGO
abrir
Referência
CVE-2011-5185
Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows re
23RIESGO
abrir
Referência
CVE-2015-7892
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RIESGO
abrir
Referência
CVE-2015-7892
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RIESGO
abrir
Referência
CVE-2026-8260
D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow
41RIESGO
abrir
Referência
CVE-2014-8347
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RIESGO
abrir
Referência
CVE-2014-8347
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RIESGO
abrir
anteriorpágina 407 / 740siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.