Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2026-6573
PHPEMS Instant Exam Creation exams.master.php temppage server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-6572
Collabora KodExplorer fileUpload Endpoint share.class.php improper authorization
33RIESGO
abrir
Referência
CVE-2026-6571
kodcloud KodExplorer systemRole.class.php roleGroupAction authorization
33RIESGO
abrir
Referência
CVE-2026-6570
kodcloud KodExplorer systemMember.class.php initInstall authorization
33RIESGO
abrir
Referência
CVE-2026-6568
kodcloud KodExplorer Public Share share.class.php initShareOld path traversal
33RIESGO
abrir
Referência
CVE-2026-6125
Dromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection
33RIESGO
abrir
Referência
CVE-2018-13832
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RIESGO
abrir
Referência
CVE-2026-8031
PicoTronica e-Clinic Healthcare System ECHS API Endpoint patient-records missing authentication
33RIESGO
abrir
Referência
CVE-2026-8028
FlowiseAI Flowise Endpoint account.service.ts verify information disclosure
33RIESGO
abrir
Referência
CVE-2026-7854
D-Link DI-8100 POST Parameter url_rule.asp url_rule_asp buffer overflow
48RIESGO
abrir
Referência
CVE-2026-7853
D-Link DI-8100 HTTP auto_reboot.asp sprintf buffer overflow
48RIESGO
abrir
Referência
CVE-2026-7851
D-Link DI-8100 yyxz.asp sprintf stack-based overflow
41RIESGO
abrir
Referência
CVE-2012-0982
SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attacke
23RIESGO
abrir
Referência
CVE-2026-15474
Eleveo Call Recording Software audio.jsp improper authorization
33RIESGO
abrir
Referência
CVE-2018-14064
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RIESGO
abrir
Referência
CVE-2018-14328
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RIESGO
abrir
Referência
CVE-2018-14485
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
28RIESGO
abrir
Referência
CVE-2018-14575
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CS
23RIESGO
abrir
Referência
CVE-2026-5655
Use After Free in Wireshark
33RIESGO
abrir
ReferênciaVexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RIESGO
abrir
Referência
CVE-2026-7686
eyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access control
33RIESGO
abrir
Referência
CVE-2026-7685
Edimax BR-6208AC setWAN buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7684
Edimax BR-6428nC setWAN buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7681
jsbroks COCO Annotator Dataset API datasets.py authorization
33RIESGO
abrir
Referência
CVE-2026-7680
jsbroks COCO Annotator Data Endpoint datasets.py path traversal
33RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - GDI+ '.ICO' File Remote Denial of Service
CVE-2007-2237doswindows
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of
28RIESGO
abrir
Referência
CVE-2026-10185
SourceCodester Hospitals Patient Records Management System Users.php save sql injection
33RIESGO
abrir
Referência
CVE-2026-10184
SourceCodester Hospitals Patient Records Management System Users.php delete sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
USP FOSS Distribution 1.01 - 'dnld' Remote File Disclosure
CVE-2007-2271webappsphp
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbi
23RIESGO
abrir
Referência
CVE-2026-10169
OUSL-GROUP-BrinaryBrains School Student Management System Forgot Password Endpoint Login.php ajax_forgot_password password recovery
33RIESGO
abrir
anteriorpágina 432 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.