Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2010-4944
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attac
23RIESGO
abrir
Referência
CVE-2010-4954
SQL injection vulnerability in product_reviews_info.php in xt:Commerce Gambio 2008 allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2026-5472
ProjectsAndPrograms School Management System Profile Picture settings.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-5471
Investory Toy Planet Trouble App app.investory.toyfactory google-services-desktop.json hard-coded key
33RIESGO
abrir
Referência
CVE-2026-5470
mixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-5462
Wahoo Fitness SYSTM App com.WahooFitness.SYSTM BuildConfig.java hard-coded key
33RIESGO
abrir
Referência
CVE-2026-5458
Noelse Individuals & Pro App com.afone.noelse BuildConfig.java hard-coded key
33RIESGO
abrir
Referência
CVE-2026-5457
PropertyGuru AgentNet Singapore App com.allproperty.android.agentnet BuildConfig.java hard-coded key
33RIESGO
abrir
Referência
CVE-2026-5456
Align Technology My Invisalign App com.aligntech.myinvisalign.emea BuildConfig.java hard-coded key
33RIESGO
abrir
Referência
CVE-2026-5455
Dialogue App ca.diagram.dialogue config.json hard-coded key
33RIESGO
abrir
Referência
CVE-2026-5454
GRID Organiser App co.gridapp.organiser app.json hard-coded key
33RIESGO
abrir
Referência
CVE-2026-5418
appsmithorg appsmith Dashboard WebClientUtils.java computeDisallowedHosts server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-5559
AntaresMugisho PyBlade AST Validation sandbox.py _is_safe_ast special elements used in a template engine
33RIESGO
abrir
Referência
CVE-2026-5558
PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection
33RIESGO
abrir
Referência
CVE-2018-25251
Snes9K 0.0.9z Buffer Overflow SEH via Netplay Socket
41RIESGO
abrir
Referência
CVE-2018-25250
MyBB Last User's Threads in Profile Plugin 1.2 Persistent XSS
33RIESGO
abrir
Referência
CVE-2018-25249
MyBB My Arcade Plugin 1.3 Persistent XSS via Comment
33RIESGO
abrir
Referência
CVE-2018-25248
MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php
33RIESGO
abrir
Referência
CVE-2018-25247
MyBB Like Plugin 3.0.0 Cross-Site Scripting via User Profiles
33RIESGO
abrir
Referência
CVE-2018-25245
7 Tik 1.0.1.0 Denial of Service via Search
41RIESGO
abrir
Referência
CVE-2018-25244
Eco Search 1.0.2.0 Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25243
FastTube 1.0.1.0 Denial of Service via Search
33RIESGO
abrir
Referência
CVE-2018-25242
One Search 1.1.0.0 Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25241
VPN Browser+ 1.1.0.0 Denial of Service
41RIESGO
abrir
Referência
CVE-2018-10068
The jDownloads extension before 3.2.59 for Joomla! has XSS.
23RIESGO
abrir
Referência
CVE-2018-10077
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to re
23RIESGO
abrir
Referência
CVE-2018-10078
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i
23RIESGO
abrir
Referência
CVE-2018-10253
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
23RIESGO
abrir
Referência
CVE-2018-10256
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RIESGO
abrir
Referência
CVE-2018-10259
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u
23RIESGO
abrir
anteriorpágina 442 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.