Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2026-1631
Feeds for YouTube < 2.6.4 - Subscriber+ License Data Deletion
33RIESGO
abrir
Referência
CVE-2018-6367
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame
23RIESGO
abrir
Referência
CVE-2018-6368
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed acti
23RIESGO
abrir
Referência
CVE-2026-4524
Authentication Bypass Using an Alternate Path or Channel in GitLab
33RIESGO
abrir
Referência
CVE-2026-4527
Cross-Site Request Forgery (CSRF) in GitLab
33RIESGO
abrir
Referência
CVE-2026-19383
saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload
33RIESGO
abrir
ReferênciaVexDay Proof
CCProxy 6.2 - 'ping' Remote Buffer Overflow
CVE-2004-2685remotewindows
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre
28RIESGO
abrir
ReferênciaVexDay Proof
CCProxy 6.2 - Telnet Proxy Ping Overflow (Metasploit)
CVE-2004-2685remotewindows
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre
28RIESGO
abrir
Referência
CVE-2018-6789
CVE-2018-6789CRITICALbajo ataqueransomware
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
Referência
CVE-2026-19195
V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control
41RIESGO
abrir
Referência
CVE-2026-19193
Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control
41RIESGO
abrir
Referência
CVE-2026-19108
MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free
33RIESGO
abrir
Referência
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
Referência
CVE-2025-15674
Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
28RIESGO
abrir
Referência
CVE-2026-16620
WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
41RIESGO
abrir
Referência
CVE-2026-16619
miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
41RIESGO
abrir
Referência
CVE-2026-19062
chiuwingyan house selectall.action sql injection
33RIESGO
abrir
Referência
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
Referência
CVE-2018-6888
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cro
23RIESGO
abrir
Referência
CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
Referência
CVE-2019-0541
CVE-2019-0541HIGHbajo ataque
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E
83RIESGO
abrir
Referência
CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Referência
CVE-2026-16532
Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form
48RIESGO
abrir
Referência
CVE-2026-12696
wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
33RIESGO
abrir
Referência
CVE-2026-15234
Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
33RIESGO
abrir
Referência
CVE-2026-15262
Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column
33RIESGO
abrir
Referência
CVE-2026-14847
Paid Member Subscriptions < 3.0.7 - Subscriber+ Payment Data Disclosure via IDOR
33RIESGO
abrir
ReferênciaVexDay Proof
Roundcube Webmail 0.2b - Remote Code Execution
CVE-2008-5619webappsphp
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RIESGO
abrir
ReferênciaVexDay Proof
phpMyAdmin 3.1.0 - Cross-Site Request Forgery / SQL Injection
CVE-2008-5621webappsphp
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remot
23RIESGO
abrir
Referência
CVE-2018-12465
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RIESGO
abrir
anteriorpágina 733 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.