Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.953exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
22.832 exploits
Referência
CVE-2026-15622
poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
33RIESGO
abrir
Referência
CVE-2026-62239
FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py
33RIESGO
abrir
ReferênciaVexDay Proof
CaupoShop Pro 2.x - 'action' Remote File Inclusion
CVE-2007-5784webappsphp
PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary P
23RIESGO
abrir
Referência
CVE-2026-12397
WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
33RIESGO
abrir
Referência
CVE-2026-15607
tanstack db Alias Path select.ts select prototype pollution
33RIESGO
abrir
Referência
CVE-2026-12780
AOMEI Backupper Kernel Driver amwrtdrv.sys access control
41RIESGO
abrir
ReferênciaVexDay Proof
Debian OpenSSH - (Authenticated) Remote SELinux Privilege Escalation
CVE-2008-3234remotelinux
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac
23RIESGO
abrir
ReferênciaVexDay Proof
IAPR COMMENCE 1.3 - Multiple Remote File Inclusions
CVE-2007-6147webappsphp
Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
CVE-2026-9822
WP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX Handlers
33RIESGO
abrir
ReferênciaVexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (2)
CVE-2008-3250webappsphp
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2018-11412
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste
28RIESGO
abrir
Referência
CVE-2018-11445
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing
23RIESGO
abrir
Referência
CVE-2026-10873
Shibby Tomato Web UI rstats rstats_path os command injection
41RIESGO
abrir
Referência
CVE-2026-10567
1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting
33RIESGO
abrir
Referência
CVE-2018-25434
WP AutoSuggest 0.24 SQL Injection via autosuggest.php
41RIESGO
abrir
Referência
CVE-2018-25433
Joomla JE Photo Gallery 1.1 SQL Injection via categoryid
41RIESGO
abrir
Referência
CVE-2018-25432
Arm Whois 3.11 Buffer Overflow via ASLR Bypass
41RIESGO
abrir
Referência
CVE-2026-10273
php-censor Webhook Endpoint GitBuild.php os command injection
33RIESGO
abrir
Referência
CVE-2026-6324
Libsoup: libsoup: http request smuggling via unsigned to signed conversion error
33RIESGO
abrir
Referência
CVE-2018-11776
CVE-2018-11776HIGHbajo ataque
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Referência
CVE-2018-11776
CVE-2018-11776HIGHbajo ataque
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
ReferênciaVexDay Proof
Plogger 3.0 - SQL Injection
CVE-2008-3563webappsphp
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2026-9606
itsourcecode Courier Management System manage_user.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9605
GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-44195
OPNsense: Authentication lockout bypass
33RIESGO
abrir
ReferênciaVexDay Proof
IP Reg 0.4 - Multiple SQL Injections
CVE-2008-4606webappsphp
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
Joomla! Component JEXTN Membership 3.1.0 - 'usr_plan' SQL Injection
CVE-2018-6577webappsphp
SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&ta
23RIESGO
abrir
ReferênciaVexDay Proof
Eurologon CMS - 'files.php' Arbitrary File Download
CVE-2007-6185webappsphp
Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files vi
23RIESGO
abrir
Referência
Joomla! Component JEXTN Reverse Auction 3.1.0 - SQL Injection
CVE-2018-6579webappsphp
SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.
23RIESGO
abrir
Referência
CVE-2019-0211
CVE-2019-0211HIGHbajo ataque
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RIESGO
abrir
anteriorpágina 736 / 762siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.