Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
ReferênciaVexDay Proof
BoatScripts Classifieds - 'type' SQL Injection
CVE-2008-2846webappsphp
SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2018-1122
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset
41RIESGO
abrir
ReferênciaVexDay Proof
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
CVE-2007-6126webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject
23RIESGO
abrir
ReferênciaVexDay Proof
WorkingOnWeb 2.0.1400 - 'events.php' SQL Injection
CVE-2007-6128webappsphp
SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Content Injector 1.52 - 'index.php?cat' SQL Injection
CVE-2007-6137webappsphp
SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2026-11998
AngularJS XSS via SCE resource URL sanitization bypass
41RIESGO
abrir
Referência
CVE-2026-11998
AngularJS XSS via SCE resource URL sanitization bypass
41RIESGO
abrir
Referência
CVE-2026-50128
Mastodon: Spoofing of attribution domains
33RIESGO
abrir
Referência
CVE-2026-8379
Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download
41RIESGO
abrir
Referência
CVE-2026-7842
Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter
33RIESGO
abrir
Referência
CVE-2026-12823
Browserbase Skills Autobrowse Trace Artifact default permission
33RIESGO
abrir
Referência
CVE-2026-12814
Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection
33RIESGO
abrir
Referência
CVE-2026-12810
Edimax BR-6478AC V2 POST Request mp command injection
33RIESGO
abrir
Referência
CVE-2018-11776
CVE-2018-11776HIGHbajo ataque
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Referência
CVE-2018-11776
CVE-2018-11776HIGHbajo ataque
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
ReferênciaVexDay Proof
Plogger 3.0 - SQL Injection
CVE-2008-3563webappsphp
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2026-6324
Libsoup: libsoup: http request smuggling via unsigned to signed conversion error
33RIESGO
abrir
Referência
CVE-2026-9606
itsourcecode Courier Management System manage_user.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9605
GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-9512
Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection
33RIESGO
abrir
Referência
CVE-2026-9511
Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection
33RIESGO
abrir
Referência
CVE-2026-9498
Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine
33RIESGO
abrir
Referência
CVE-2018-5981
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
23RIESGO
abrir
Referência
CVE-2018-5982
SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= requ
23RIESGO
abrir
Referência
CVE-2026-44195
OPNsense: Authentication lockout bypass
33RIESGO
abrir
Referência
CVE-2026-73033
Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php
41RIESGO
abrir
ReferênciaVexDay Proof
IP Reg 0.4 - Multiple SQL Injections
CVE-2008-4606webappsphp
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2026-19089
Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
Referência
Joomla! Component JEXTN Membership 3.1.0 - 'usr_plan' SQL Injection
CVE-2018-6577webappsphp
SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&ta
23RIESGO
abrir
ReferênciaVexDay Proof
Eurologon CMS - 'files.php' Arbitrary File Download
CVE-2007-6185webappsphp
Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files vi
23RIESGO
abrir
anteriorpágina 735 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.