Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2026-33017
CVE-2026-33017CRITICALbajo ataque
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
Referência
CVE-2012-4865
Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file.
23RIESGO
abrir
Referência
CVE-2019-3859
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_req
48RIESGO
abrir
Referência
CVE-2025-14558
Remote code execution via ND6 Router Advertisements
56RIESGO
abrir
Referência
CVE-2018-10018
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo
23RIESGO
abrir
Referência
CVE-2014-10037
Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a ..
43RIESGO
abrir
ReferênciaVexDay Proof
phosheezy 2.0 - Remote Command Execution
CVE-2009-0250webappsphp
Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
Referência
CVE-2017-2469
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Referência
CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
ReferênciaVexDay Proof
Jaws 0.8.8 - Multiple Local File Inclusions
CVE-2009-0645webappsphp
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v
23RIESGO
abrir
ReferênciaVexDay Proof
ZZ FlashChat 3.1 - 'help.php' Local File Inclusion
CVE-2007-5620webappsphp
Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to inclu
23RIESGO
abrir
ReferênciaVexDay Proof
W1L3D4 philboard 1.0 - 'philboard_reply.asp' SQL Injection
CVE-2008-1939webappsasp
Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
QNX Neutrino 0.8.4 Atomic Edition - Remote Code Execution
CVE-2008-3150webappsphp
Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modi
23RIESGO
abrir
Referência
CVE-2010-5045
Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2009-4451
Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary co
23RIESGO
abrir
Referência
CVE-2009-4819
Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2023-4173
mooSocial mooStore index cross site scripting
43RIESGO
abrir
Referência
CVE-2010-5028
SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to e
38RIESGO
abrir
Referência
CVE-2015-1480
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive tic
23RIESGO
abrir
Referência
CVE-2015-1480
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive tic
23RIESGO
abrir
Referência
CVE-2015-2824
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke
23RIESGO
abrir
Referência
CVE-2015-2824
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke
23RIESGO
abrir
Referência
CVE-2010-1353
Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to re
43RIESGO
abrir
Referência
CVE-2009-2334
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access t
23RIESGO
abrir
Referência
CVE-2017-13798
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Referência
CVE-2009-3515
Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to inc
23RIESGO
abrir
Referência
CVE-2014-4034
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2014-4034
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2015-7986
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a deni
23RIESGO
abrir
ReferênciaVexDay Proof
Flip 3.0 - Remote Password Hash Disclosure
CVE-2007-5063webappsphp
Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, w
23RIESGO
abrir
anteriorpágina 565 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.