Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
22.657 exploits
Referência
CVE-2019-25691
Faleemi Desktop Software 1.8 Local Buffer Overflow SEH DEP Bypass
41RIESGO
abrir
Referência
CVE-2019-25689
HTML5 Video Player 1.2.5 Local Buffer Overflow Non-SEH
41RIESGO
abrir
Referência
CVE-2018-25258
RGui 3.5.0 Local Buffer Overflow SEH DEP Bypass
41RIESGO
abrir
Referência
CVE-2018-25257
Adianti Framework 5.5.0 and 5.6.0 SQL Injection via Profile
41RIESGO
abrir
Referência
CVE-2017-20239
MDwiki Cross-Site Scripting via Location Hash Parameter
33RIESGO
abrir
Referência
CVE-2026-6126
zhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authentication
33RIESGO
abrir
ReferênciaVexDay Proof
Chaussette 080706 - '_BASE' Remote File Inclusion
CVE-2006-4159webappsphp
Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute ar
28RIESGO
abrir
Referência
CVE-2010-4280
Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary
23RIESGO
abrir
Referência
CVE-2017-7690
Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary w
23RIESGO
abrir
Referência
CVE-2026-14440
Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records
41RIESGO
abrir
Referência
CVE-2026-58451
Horde IMP < 7.0.1 Path Traversal via Compose.php img src
41RIESGO
abrir
Referência
CVE-2026-65708
sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController
41RIESGO
abrir
Referência
CVE-2026-12688
ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery
33RIESGO
abrir
Referência
CVE-2026-16763
localstack serverless-localstack Configuration index.js os command injection
33RIESGO
abrir
Referência
CVE-2026-19699
GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure
28RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Post Card 1.02 - 'catid' SQL Injection
CVE-2008-6622webappsphp
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows
23RIESGO
abrir
Referência
CVE-2026-19697
GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload
33RIESGO
abrir
Referência
CVE-2026-19615
Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC
33RIESGO
abrir
Referência
CVE-2026-13552
itsourcecode Online Hotel Management System controller.php edit sql injection
33RIESGO
abrir
Referência
CVE-2026-13551
itsourcecode Baptism Information Management System editBaptism.php sql injection
33RIESGO
abrir
Referência
CVE-2026-13550
itsourcecode Baptism Information Management System delbaptism.php sql injection
33RIESGO
abrir
Referência
CVE-2026-76591
TRENDnet TEW-755AP ssi email.cgi log_email_server command injection
33RIESGO
abrir
Referência
CVE-2026-18466
WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation
33RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Petition 1.02/2.0/3.0 - Authentication Bypass
CVE-2008-6624webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2010-4282
Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute a
43RIESGO
abrir
Referência
CVE-2026-76004
UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow
48RIESGO
abrir
Referência
CVE-2026-76003
UTT HiPER 1200GW formGroupConfig strcpy stack-based overflow
48RIESGO
abrir
Referência
CVE-2026-75986
code-projects Online Job Portal System Password Recovery ForPass.php sql injection
33RIESGO
abrir
Referência
CVE-2016-5063
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RIESGO
abrir
Referência
CVE-2026-65916
CyberPanel Missing Authorization in cancelBackupCreation Handler
41RIESGO
abrir
anteriorpágina 679 / 756siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.