Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.284exploits catalogados
35.465CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2018-0748
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RIESGO
abrir
Referência
CVE-2018-25287
Drive Power Manager 1.10 Denial of Service via Name Field
33RIESGO
abrir
Referência
CVE-2018-25286
Easy PhotoResQ 1.0 Buffer Overflow Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25285
Fathom 2.4 Denial of Service via Authorization Code Buffer Overflow
33RIESGO
abrir
Referência
CVE-2018-25284
HD Tune Pro 5.70 Denial of Service via Options Dialog
33RIESGO
abrir
Referência
CVE-2018-25283
iSmartViewPro 1.5 Buffer Overflow via SavePath Parameter
41RIESGO
abrir
Referência
CVE-2018-25282
Nmap 7.70 Denial of Service via XML Entity Expansion
33RIESGO
abrir
Referência
CVE-2018-25281
iCash 7.6.5 Denial of Service via Connect to Server
33RIESGO
abrir
Referência
CVE-2018-25280
Infiltrator Network Security Scanner 4.6 Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25279
jiNa OCR Image to Text 1.0 Denial of Service via PNG
33RIESGO
abrir
Referência
CVE-2018-25278
PicaJet FX 2.6.5 Denial of Service via Registration Fields
33RIESGO
abrir
Referência
CVE-2018-0752
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RIESGO
abrir
Referência
CVE-2018-0823
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RIESGO
abrir
Referência
CVE-2026-5806
code-projects Easy Blog Site update.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5805
code-projects Easy Blog Site contact_us.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5803
bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-5802
idachev mcp-javadc HTTP os command injection
33RIESGO
abrir
Referência
CVE-2026-4338
ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure
41RIESGO
abrir
Referência
CVE-2026-5741
suvarchal docker-mcp-server HTTP index.ts pull_image os command injection
33RIESGO
abrir
Referência
CVE-2018-0838
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RIESGO
abrir
Referência
CVE-2018-0860
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RIESGO
abrir
Referência
CVE-2018-25240
Watchr 1.1.0.0 Denial of Service via Search
33RIESGO
abrir
Referência
CVE-2018-25239
Smart VPN 1.1.3.0 Denial of Service via Search
33RIESGO
abrir
Referência
CVE-2018-25238
VSCO 1.1.1.0 Denial of Service via Search
33RIESGO
abrir
Referência
CVE-2016-20061
sheed AntiVirus 2.3 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20060
Hotspot Shield 6.0.3 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20059
IObit Malware Fighter 4.3.1 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20058
Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20057
NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20052
Snews CMS 1.7 Unrestricted File Upload via snews_files
48RIESGO
abrir
anteriorpágina 443 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.