Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
ReferênciaVexDay Proof
DataTrac Activity Console - Denial of Service
CVE-2005-1667doswindows
DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.
23RIESGO
abrir
Referência
CVE-2011-5130
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers t
50RIESGO
abrir
Referência
CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
Referência
CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
Referência
CVE-2026-16228
SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
33RIESGO
abrir
Referência
CVE-2014-8739
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir
Referência
CVE-2017-1274
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated
23RIESGO
abrir
Referência
CVE-2020-37168
Ecommerce Systempay 1.0 Production Key Brute Force
48RIESGO
abrir
Referência
CVE-2026-9810
AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuth
48RIESGO
abrir
Referência
CVE-2017-12786
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40
28RIESGO
abrir
ReferênciaVexDay Proof
ActiveBuyandSell 6.2 - 'buyersend.asp?catid' SQL Injection
CVE-2005-2062webappsasp
Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2014-9004
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Referência
CVE-2026-59258
immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser
41RIESGO
abrir
Referência
CVE-2021-47929
WordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS
33RIESGO
abrir
Referência
CVE-2021-47928
Opencart TMD Vendor System 3.x Blind SQL Injection via product route
41RIESGO
abrir
Referência
CVE-2021-47923
OpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie
48RIESGO
abrir
Referência
CVE-2011-5204
Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading fr
23RIESGO
abrir
Referência
CVE-2005-2428
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RIESGO
abrir
Referência
CVE-2014-9095
Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary S
23RIESGO
abrir
Referência
CVE-2026-14642
SourceCodester Class and Exam Timetabling System edit_class2.php sql injection
33RIESGO
abrir
Referência
CVE-2026-14641
SourceCodester Class and Exam Timetabling System edit_course.php sql injection
33RIESGO
abrir
Referência
CVE-2026-14640
CodeAstro Apartment Visitor Management System Login index.php sql injection
33RIESGO
abrir
Referência
CVE-2026-14639
CodeAstro Ecommerce Website my_account.php sql injection
33RIESGO
abrir
Referência
CVE-2026-14633
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Hidden REST API Endpoint set cross site scripting
33RIESGO
abrir
Referência
CVE-2026-14607
RT-Thread lwp_syscall.c sys_getaddrinfo memory corruption
33RIESGO
abrir
Referência
CVE-2014-9097
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly
23RIESGO
abrir
Referência
CVE-2026-8207
Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/gr
41RIESGO
abrir
Referência
Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
CVE-2020-15255HIGHwebappsphp
CSV injection in Anuko Time Tracker
41RIESGO
abrir
Referência
CVE-2017-20265
Joomla! Component Flip Wall 8.0 SQL Injection
41RIESGO
abrir
Referência
CVE-2011-5283
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Expre
23RIESGO
abrir
anteriorpágina 710 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.