Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2026-8242
Industrial Application Software IAS Canias ERP Login RMI doAction response discrepancy
33RIESGO
abrir
Referência
CVE-2026-8241
Industrial Application Software IAS Canias ERP RMI iasGetServerInfoEvent improper authorization
33RIESGO
abrir
Referência
CVE-2026-8235
8421bit MiniClaw System kernel.ts resolveSkillScriptPath os command injection
33RIESGO
abrir
Referência
CVE-2026-8229
Wavlink NU516U1 wireless.cgi WifiBasic os command injection
33RIESGO
abrir
Referência
CVE-2026-8228
Wavlink NU516U1 wireless.cgi advance os command injection
33RIESGO
abrir
Referência
CVE-2026-8227
Wavlink NU516U1 adm.cgi wzdapMesh os command injection
33RIESGO
abrir
Referência
CVE-2026-8226
Open5GS types.c ogs_pcc_rule_install_flow_from_media denial of service
33RIESGO
abrir
Referência
CVE-2026-8225
Open5GS delete Endpoint sm-sm.c pcf_npcf_smpolicycontrol_handle_delete denial of service
33RIESGO
abrir
Referência
CVE-2026-8195
JeecgBoot SVG File CommonController.java cross site scripting
33RIESGO
abrir
Referência
CVE-2026-8190
Wavlink NU516U1 adm.cgi wan os command injection
33RIESGO
abrir
Referência
CVE-2026-8209
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction
33RIESGO
abrir
Referência
CVE-2014-5144
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (2)
CVE-2006-7210doswindows
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (3)
CVE-2006-7210doswindows
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RIESGO
abrir
Referência
CVE-2015-8429
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Referência
CVE-2015-8430
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Referência
CVE-2026-18813
H3C NX15 esps delete command injection
41RIESGO
abrir
Referência
Froxlor 0.10.29.1 - SQL Injection (Authenticated)
CVE-2021-42325webappsphp
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
28RIESGO
abrir
Referência
CVE-2021-42362
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RIESGO
abrir
Referência
CVE-2021-42580
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm
23RIESGO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
ReferênciaVexDay Proof
Apple QuickTime - 'rtsp URL Handler' Remote Stack Buffer Overflow
CVE-2007-0015remotemultiple
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RIESGO
abrir
Referência
CVE-2021-43481
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
23RIESGO
abrir
Referência
CVE-2021-43798
CVE-2021-43798HIGHbajo ataque
Grafana path traversal
100RIESGO
abrir
Referência
CVE-2015-9098
In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Mon
28RIESGO
abrir
Referência
CVE-2016-0006
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RIESGO
abrir
Referência
CVE-2016-0040
CVE-2016-0040HIGHbajo ataque
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
anteriorpágina 502 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.