Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.331exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2026-19613
ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source
33RIESGO
abrir
ReferênciaVexDay Proof
GNUTURK 2G - 't_id' SQL Injection
CVE-2006-4867webappsphp
SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
CVE-2006-6879webappsphp
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
CVE-2006-6879webappsphp
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RIESGO
abrir
Referência
CVE-2016-1336
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a
23RIESGO
abrir
Referência
CVE-2016-1464
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code
28RIESGO
abrir
Referência
CVE-2006-7127
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2026-8268
Open5GS SMF OpenAPI_list_create denial of service
33RIESGO
abrir
Referência
CVE-2026-8265
Tenda AC6 httpd getLogFile get_log_file os command injection
33RIESGO
abrir
Referência
CVE-2026-8264
Tenda AC6 httpd WifiApScan formWifiApScan os command injection
33RIESGO
abrir
Referência
CVE-2026-8263
Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection
33RIESGO
abrir
Referência
CVE-2026-8262
Devs Palace ERP Online chart-save cross site scripting
33RIESGO
abrir
Referência
CVE-2026-8261
Squirrel sqobject.cpp Load heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-8258
Squirrel sqstdstring.cpp validate_format stack-based overflow
33RIESGO
abrir
Referência
CVE-2026-8250
Open5GS SMF n4-build.c smf_n4_build_qos_flow_to_modify_list denial of service
33RIESGO
abrir
Referência
CVE-2026-8249
Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
33RIESGO
abrir
Referência
CVE-2021-47930
Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated
41RIESGO
abrir
Referência
CVE-2021-47910
WordPress Plugin AccessPress Social Icons 1.8.2 Stored XSS
33RIESGO
abrir
Referência
CVE-2022-50969
uBidAuction 2.0.1 mailingLog manage Reflected XSS
33RIESGO
abrir
Referência
CVE-2022-50968
uBidAuction 2.0.1 auctions manage Reflected XSS
33RIESGO
abrir
Referência
CVE-2022-50967
uBidAuction 2.0.1 tickets manage Reflected XSS
33RIESGO
abrir
Referência
CVE-2016-1524
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RIESGO
abrir
Referência
CVE-2016-1525
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RIESGO
abrir
Referência
CVE-2026-18900
H3C NX15 Backend RPC esps file.exec os command injection
41RIESGO
abrir
Referência
CVE-2016-1823
The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and wa
28RIESGO
abrir
ReferênciaVexDay Proof
PBLang 4.66z - 'temppath' Remote File Inclusion
CVE-2006-5062webappsphp
PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows re
23RIESGO
abrir
Referência
CVE-2016-2107
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RIESGO
abrir
ReferênciaVexDay Proof
PHP-Stats 0.1.9.1b - 'ip' SQL Injection
CVE-2006-7172webappsphp
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers
23RIESGO
abrir
Referência
CVE-2016-3672
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize t
23RIESGO
abrir
Referência
CVE-2026-18813
H3C NX15 esps delete command injection
41RIESGO
abrir
anteriorpágina 716 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.