Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2019-12989
CVE-2019-12989CRITICALbajo ataque
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
100RIESGO
abrir
Referência
CVE-2018-3245
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RIESGO
abrir
Referência
CVE-2010-4915
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Calendar MX Professional 2.0.0 - Blind SQL Injection
CVE-2008-6378webappsasp
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Gallery MX 2.0.0 - Blind SQL Injection
CVE-2008-6379webappsasp
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Referência
CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Referência
CVE-2016-1524
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RIESGO
abrir
ReferênciaVexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
CVE-2008-6380webappsphp
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (2)
CVE-2007-0388webappsphp
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RIESGO
abrir
ReferênciaVexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
CVE-2008-6387webappsphp
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir
Referência
CVE-2026-21643
CVE-2026-21643CRITICALbajo ataque
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
100RIESGO
abrir
Referência
CVE-2024-48248
CVE-2024-48248HIGHbajo ataque
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RIESGO
abrir
Referência
CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
Referência
CVE-2023-36845
CVE-2023-36845CRITICALbajo ataque
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
Referência
CVE-2023-36845
CVE-2023-36845CRITICALbajo ataque
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
Referência
CVE-2021-44077
CVE-2021-44077CRITICALbajo ataque
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RIESGO
abrir
ReferênciaVexDay Proof
Psi Jabber Client (Windows / Linux) - Remote Denial of Service
CVE-2008-6393dosmultiple
PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitr
28RIESGO
abrir
Referência
CVE-2008-6396
Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject ar
23RIESGO
abrir
Referência
CVE-2026-7219
Totolink N300RT formIpQoS buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7218
Totolink N300RT libapmib.so formWsc is_cmd_string_valid buffer overflow
41RIESGO
abrir
Referência
Microsoft Windows Server 2016 - Win32k Elevation of Privilege
CVE-2023-29336HIGHbajo ataquelocalwindows
Win32k Elevation of Privilege Vulnerability
83RIESGO
abrir
Referência
Companymaps v8.0 - Stored Cross Site Scripting (XSS)
CVE-2023-29983MEDIUMwebappsphp
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary co
33RIESGO
abrir
Referência
CVE-2018-10561
CVE-2018-10561CRITICALbajo ataque
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RIESGO
abrir
Referência
CVE-2019-1653
CVE-2019-1653HIGHbajo ataque
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
Referência
CVE-2019-8943
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Referência
CVE-2019-8943
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Referência
CVE-2019-8943
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Referência
CVE-2019-8943
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Referência
CVE-2023-31069
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML s
23RIESGO
abrir
anteriorpágina 507 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.