Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2008-4648
Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to injec
23RIESGO
abrir
Referência
CVE-2012-10053
Simple Web Server Connection Header Buffer Overflow
63RIESGO
abrir
Referência
CVE-2012-10053
Simple Web Server Connection Header Buffer Overflow
63RIESGO
abrir
Referência
CVE-2012-10053
Simple Web Server Connection Header Buffer Overflow
63RIESGO
abrir
Referência
CVE-2012-10053
Simple Web Server Connection Header Buffer Overflow
63RIESGO
abrir
Referência
CVE-2009-4822
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject
23RIESGO
abrir
Referência
CVE-2015-7891
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A
23RIESGO
abrir
Referência
CVE-2015-7891
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A
23RIESGO
abrir
Referência
CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
Referência
CVE-2012-6518
Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authenti
23RIESGO
abrir
Referência
CVE-2026-19613
ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source
33RIESGO
abrir
Referência
CVE-2025-34149
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via WPA2 Key
48RIESGO
abrir
Referência
CVE-2023-54339
Webgrind 1.1 - Remote Command Execution (RCE) via dataFile Parameter
48RIESGO
abrir
Referência
CVE-2017-3587
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder). Supported ve
23RIESGO
abrir
Referência
CVE-2015-5602
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RIESGO
abrir
Referência
CVE-2008-6386
Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary we
23RIESGO
abrir
Referência
CVE-2014-9632
The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protec
23RIESGO
abrir
Referência
CVE-2014-9632
The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protec
23RIESGO
abrir
Referência
CVE-2025-34433
AVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt
63RIESGO
abrir
Referência
CVE-2013-6922
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg200
23RIESGO
abrir
Referência
CVE-2025-10432
Tenda AC1206 HTTP Request AdvSetMacMtuWa check_param_changed stack-based overflow
48RIESGO
abrir
Referência
CVE-2010-2439
Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list
23RIESGO
abrir
Referência
CVE-2015-7894
The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow
23RIESGO
abrir
Referência
CVE-2026-18653
WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter
41RIESGO
abrir
Referência
CVE-2012-6434
Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attacke
23RIESGO
abrir
Referência
CVE-2017-7952
INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.
23RIESGO
abrir
Referência
CVE-2025-25037
Aquatronica Controller System Complete Information Disclosure
63RIESGO
abrir
Referência
CVE-2025-25037
Aquatronica Controller System Complete Information Disclosure
63RIESGO
abrir
Referência
CVE-2022-50796
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi
48RIESGO
abrir
Referência
CVE-2012-10037
PhpTax pfilez Parameter Exec Remote Code Injection
63RIESGO
abrir
anteriorpágina 653 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.