Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.866exploits catalogados
35.812CVEs con explotación pública
24.695probados en laboratorio
22.549 exploits
Referência
CVE-2009-4186
Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (a
23RIESGO
abrir
Referência
CVE-2020-37225
Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site Scripting
33RIESGO
abrir
Referência
CVE-2020-37224
Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via sortby
41RIESGO
abrir
Referência
CVE-2020-37223
IObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2020-37222
Kuicms Php EE 2.0 Persistent Cross-Site Scripting via bbs reply
33RIESGO
abrir
Referência
CVE-2014-4613
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke
23RIESGO
abrir
Referência
CVE-2014-4663
TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2014-4852
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to
23RIESGO
abrir
Referência
CVE-2014-4873
SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to
23RIESGO
abrir
Referência
CVE-2014-4960
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x throu
23RIESGO
abrir
Referência
CVE-2009-4596
Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary w
23RIESGO
abrir
Referência
CVE-2014-4960
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x throu
23RIESGO
abrir
Referência
CVE-2014-4971
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir
Referência
CVE-2026-73482
phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php
41RIESGO
abrir
Referência
CVE-2019-25765
ASP-CMS SQL Injection via commentList.asp id Parameter
41RIESGO
abrir
Referência
CVE-2015-4877
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RIESGO
abrir
Referência
CVE-2024-58374
Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree
41RIESGO
abrir
Referência
CVE-2026-59109
Zalktis: SQL injection via partner-controlled fields in imported e-invoices
41RIESGO
abrir
Referência
CVE-2026-73515
PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer
41RIESGO
abrir
Referência
CVE-2026-14332
Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action
33RIESGO
abrir
Referência
CVE-2026-19088
ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication
33RIESGO
abrir
Referência
CVE-2026-18945
WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation
41RIESGO
abrir
Referência
CVE-2026-14213
Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR
28RIESGO
abrir
Referência
CVE-2026-14182
Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass
48RIESGO
abrir
Referência
CVE-2026-13610
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RIESGO
abrir
Referência
CVE-2026-13328
TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification
33RIESGO
abrir
Referência
CVE-2026-18391
WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection
48RIESGO
abrir
Referência
CVE-2026-18366
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RIESGO
abrir
Referência
CVE-2026-18230
WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter
41RIESGO
abrir
Referência
CVE-2026-18057
Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection
41RIESGO
abrir
anteriorpágina 598 / 752siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.