Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
22.832 exploits
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6496webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to host
23RIESGO
abrir
ReferênciaVexDay Proof
DELTAScripts PHP Shop 1.0 - Authentication Bypass
CVE-2008-5648webappsphp
SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
WinFTP Server 2.3.0 - 'PASV Mode' Remote Denial of Service
CVE-2008-5666doswindows
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6497webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a reque
23RIESGO
abrir
Referência
CVE-2018-12602
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
23RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6503webappsasp
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Page Flip Image Gallery 0.2.2 - Remote File Disclosure
CVE-2008-5752webappsphp
Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress
23RIESGO
abrir
Referência
CVE-2008-5753
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
CVE-2008-5753doswindows
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2018-13108
All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerabilit
23RIESGO
abrir
Referência
CVE-2026-38764
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
41RIESGO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir
Referência
CVE-2026-16628
oclif JIT Plugin Entry child_process.exec os command injection
33RIESGO
abrir
Referência
CVE-2026-11579
Kali Forms < 2.4.17 - Unauthenticated Media Upload
33RIESGO
abrir
Referência
CVE-2026-12968
Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload
41RIESGO
abrir
Referência
CVE-2026-8989
Open Recovery Mode
41RIESGO
abrir
Referência
CVE-2026-16449
zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection
33RIESGO
abrir
Referência
CVE-2026-16331
D-Link DNS-320 save_ajax.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-16330
D-Link DNS-320 uploadify.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-13402
Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
33RIESGO
abrir
Referência
CVE-2026-12869
Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import
33RIESGO
abrir
Referência
CVE-2026-15907
H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
33RIESGO
abrir
Referência
CVE-2026-8988
Access to Bootloader
41RIESGO
abrir
Referência
CVE-2026-63770
Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
41RIESGO
abrir
Referência
CVE-2026-63771
Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
33RIESGO
abrir
Referência
CVE-2026-16009
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
33RIESGO
abrir
Referência
CVE-2026-12684
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RIESGO
abrir
Referência
CVE-2026-12585
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
41RIESGO
abrir
Referência
CVE-2026-15520
GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-15518
AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload
33RIESGO
abrir
anteriorpágina 740 / 762siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.