Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2012-2572
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote a
23RIESGO
abrir
Referência
CVE-2018-17128
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
45RIESGO
abrir
Referência
CVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RIESGO
abrir
Referência
CVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RIESGO
abrir
Referência
CVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RIESGO
abrir
Referência
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RIESGO
abrir
Referência
CVE-2026-6182
code-projects Simple Content Management System login.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6204
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Bina
41RIESGO
abrir
Referência
CVE-2026-2728
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig pa
33RIESGO
abrir
Referência
CVE-2025-15632
1Panel-dev MaxKB MdPreview chat.ts cross site scripting
33RIESGO
abrir
Referência
CVE-2026-6167
code-projects Faculty Management System subject-print.php sql injection
33RIESGO
abrir
Referência
CVE-2010-5236
Untrusted search path vulnerability in Roxio Easy Media Creator Home 9.0.136 allows local users to gain privileges via a
23RIESGO
abrir
Referência
CVE-2026-7407
SourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection
33RIESGO
abrir
Referência
CVE-2026-7404
getsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversal
33RIESGO
abrir
Referência
CVE-2024-58344
Carbon Forum 5.9.0 Persistent XSS via Forum Name Field
33RIESGO
abrir
Referência
CVE-2018-25272
ELBA5 5.8.0 Remote Code Execution via Database Access
48RIESGO
abrir
Referência
CVE-2018-25271
Textpad 8.1.2 Denial of Service via Run Command
33RIESGO
abrir
Referência
CVE-2018-25270
ThinkPHP 5.0.23 Remote Code Execution via invokefunction
48RIESGO
abrir
Referência
CVE-2018-25269
ICEWARP 11.0.0.0 Cross-Site Scripting via Email HTML Injection
33RIESGO
abrir
Referência
CVE-2018-25268
LanSpy 2.0.1.159 Local Buffer Overflow via Scan Field
41RIESGO
abrir
Referência
CVE-2018-25267
UltraISO 9.7.1.3519 Buffer Overflow via Output FileName
33RIESGO
abrir
Referência
CVE-2018-25266
Angry IP Scanner 3.5.3 Denial of Service via Preferences Buffer Overflow
33RIESGO
abrir
Referência
CVE-2018-25265
LanSpy 2.0.1.159 Local Buffer Overflow
41RIESGO
abrir
Referência
CVE-2018-25262
Angry IP Scanner for Linux 3.5.3 Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25261
Iperius Backup 5.8.1 Local Buffer Overflow SEH
41RIESGO
abrir
Referência
CVE-2018-25260
MAGIX Music Editor 3.1 Buffer Overflow via SEH
41RIESGO
abrir
Referência
CVE-2018-25259
Terminal Services Manager 3.1 Buffer Overflow SEH
41RIESGO
abrir
Referência
CVE-2026-7403
geldata gel-mcp server.py fetch_rule path traversal
33RIESGO
abrir
Referência
CVE-2026-34965
Cockpit CMS Authenticated Remote Code Execution via Collections
41RIESGO
abrir
Referência
CVE-2018-25311
VideoFlow Digital Video Protection DVP 2.10 Authenticated Directory Traversal
41RIESGO
abrir
anteriorpágina 448 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.