Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2017-20262
Joomla! Component Ajax Quiz 1.8 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20257
Joomla! Component Quiz Deluxe 3.7.4 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20256
Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
41RIESGO
abrir
Referência
CVE-2017-20255
Joomla! Component JB Visa 1.0 SQL Injection via visatype
41RIESGO
abrir
Referência
CVE-2017-20254
Joomla! Component User Bench 1.0 SQL Injection via userid
41RIESGO
abrir
Referência
CVE-2017-20253
Joomla! Component My Projects 2.0 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20252
Joomla NextGen Editor 2.1.0 SQL Injection via plname Parameter
41RIESGO
abrir
Referência
CVE-2023-54353
Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20071
WordPress 404 Redirection Manager Plugin 1.0 SQL Injection
41RIESGO
abrir
Referência
CVE-2016-20070
WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS
33RIESGO
abrir
Referência
CVE-2026-10811
itsourcecode Fees Management System receipt.php sql injection
33RIESGO
abrir
Referência
CVE-2026-10550
elunez eladmin Application Deployment App.java command injection
33RIESGO
abrir
Referência
CVE-2026-10548
NousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authentication
33RIESGO
abrir
Referência
CVE-2026-10301
itsourcecode Fees Management System index.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-10295
SourceCodester Customer Review App review_app.py get_all_reviews denial of service
33RIESGO
abrir
Referência
CVE-2026-10292
UTT HiPER 1200GW formTaskEdit strcpy stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-10290
code-projects Hotel and Tourism Reservation System GET Parameter tour.php sql injection
33RIESGO
abrir
Referência
CVE-2026-10289
code-projects Hotel and Tourism Reservation System tour.php cross site scripting
33RIESGO
abrir
Referência
CVE-2018-8467
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Referência
CVE-2026-12189
Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
33RIESGO
abrir
Referência
CVE-2026-12187
GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection
41RIESGO
abrir
Referência
CVE-2026-12186
GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection
41RIESGO
abrir
Referência
CVE-2025-15546
Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition
33RIESGO
abrir
Referência
CVE-2026-12174
D-Link DCS-935L HTTP rhea snprintf format string
41RIESGO
abrir
Referência
CVE-2026-25557
Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter
33RIESGO
abrir
Referência
CVE-2004-0798
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to
50RIESGO
abrir
Referência
CVE-2018-8734
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir
Referência
CVE-2026-11621
Dcat-Admin User Setting upload editorMDUpload unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-11584
CodeAstro Student Attendance Management System createClass.php edit sql injection
33RIESGO
abrir
Referência
CVE-2026-11583
CodeAstro Student Attendance Management System createClass.php sql injection
33RIESGO
abrir
anteriorpágina 501 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.