Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.301 exploits
Referência
CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
ReferênciaVexDay Proof
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
CVE-2020-11455webappsphp
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileM
60RIESGO
abrir
Referência
LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
CVE-2020-11456webappsphp
LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and applicati
45RIESGO
abrir
Referência
CVE-2020-1147
CVE-2020-1147HIGHbajo ataque
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RIESGO
abrir
Referência
CVE-2026-16228
SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
33RIESGO
abrir
Referência
CVE-2015-1635
CVE-2015-1635CRITICALbajo ataque
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Referência
CVE-2015-1635
CVE-2015-1635CRITICALbajo ataque
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Referência
CVE-2015-1635
CVE-2015-1635CRITICALbajo ataque
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Referência
CVE-2026-8733
Investintech SlimPDFReader SlimPDFReader.exe sub_3B4610 stack-based overflow
33RIESGO
abrir
ReferênciaVexDay Proof
SkaLinks 1.5 - Authentication Bypass
CVE-2009-0451webappsphp
SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Adm
23RIESGO
abrir
ReferênciaVexDay Proof
Online Grades 3.2.4 - Authentication Bypass
CVE-2009-0452webappsphp
Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, a
23RIESGO
abrir
Referência
CVE-2026-8731
Open5GS NRF client.c ogs_sbi_client_add denial of service
33RIESGO
abrir
Referência
CVE-2026-8730
Open5GS NRF context.c ogs_sbi_nf_instance_set_id denial of service
33RIESGO
abrir
Referência
CVE-2026-8728
Open5GS NRF conv.c ogs_sbi_discovery_option_parse_plmn_list denial of service
33RIESGO
abrir
Referência
CVE-2011-5166
Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string
23RIESGO
abrir
Referência
CVE-2026-8725
CoreWorxLab CAAL test-hass Endpoint webhooks.py server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-8724
Dataease Data Dashboard SqlparserUtils.java SqlparserUtils.transFilter sql injection
33RIESGO
abrir
Referência
CVE-2020-11978
CVE-2020-11978HIGHbajo ataque
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RIESGO
abrir
Referência
CVE-2020-13379
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows
60RIESGO
abrir
Referência
CVE-2020-13693
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi
35RIESGO
abrir
Referência
CVE-2020-13927
CVE-2020-13927CRITICALbajo ataque
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RIESGO
abrir
Referência
CVE-2020-13927
CVE-2020-13927CRITICALbajo ataque
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RIESGO
abrir
Referência
CVE-2020-13951
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
45RIESGO
abrir
Referência
CVE-2020-37168
Ecommerce Systempay 1.0 Production Key Brute Force
48RIESGO
abrir
Referência
CVE-2011-5183
Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2026-8345
D-Link DIR-816 singlePortForward sub_445E7C command injection
33RIESGO
abrir
Referência
CVE-2026-8344
D-Link DIR-816 formDMZ.cgi sub_445E7C command injection
33RIESGO
abrir
Referência
CVE-2026-43884
WWBN AVideo: SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()
41RIESGO
abrir
ReferênciaVexDay Proof
POP Peeper 3.4.0.0 - Date Remote Buffer Overflow
CVE-2009-1029remotewindows
Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a
50RIESGO
abrir
Referência
CVE-2026-8305
OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authentication
33RIESGO
abrir
anteriorpágina 471 / 744siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.