Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.325exploits catalogados
36.055CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2016-0049
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RIESGO
abrir
Referência
CVE-2026-19928
OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges management
33RIESGO
abrir
Referência
CVE-2018-14335
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read
38RIESGO
abrir
Referência
CVE-2026-19927
OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-19926
Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection
33RIESGO
abrir
Referência
CVE-2017-1000373
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N
28RIESGO
abrir
Referência
CVE-2011-4713
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arb
23RIESGO
abrir
Referência
CVE-2017-10661
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denia
28RIESGO
abrir
Referência
CVE-2018-8298
CVE-2018-8298HIGHbajo ataque
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RIESGO
abrir
Referência
CVE-2022-20707
Cisco Small Business RV Series Routers Vulnerabilities
85RIESGO
abrir
Referência
CVE-2021-36711
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
28RIESGO
abrir
Referência
CVE-2010-1885
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server
60RIESGO
abrir
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1495webappsphp
Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote auth
23RIESGO
abrir
ReferênciaVexDay Proof
NetWin Surgemail 3.8k4-4 - IMAP (Authenticated) Remote LIST Universal
CVE-2008-1498remotewindows
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated user
23RIESGO
abrir
Referência
CVE-2021-38759
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain a
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component custompages 1.1 - Remote File Inclusion
CVE-2008-1505webappsphp
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joo
35RIESGO
abrir
ReferênciaVexDay Proof
Danneo CMS 0.5.1 - Blind SQL Injection
CVE-2008-1513webappsphp
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled
23RIESGO
abrir
Referência
CVE-2021-39312
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
CVE-2008-1539webappsphp
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
CVE-2008-1551webappsphp
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2021-39316
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
68RIESGO
abrir
Referência
CVE-2011-4808
SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
TopperMod 2.0 - SQL Injection
CVE-2008-1554webappsphp
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
D-Link DWL-2000AP 2.11 - ARP Flood Remote Denial of Service
CVE-2006-6538doshardware
D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of
23RIESGO
abrir
ReferênciaVexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
CVE-2008-1558doslinux
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RIESGO
abrir
ReferênciaVexDay Proof
Fantastic News 2.1.4 - 'news.php' SQL Injection
CVE-2006-6542webappsphp
SQL injection vulnerability in news.php in Fantastic News 2.1.4 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Alphacontent 2.5.8 - 'id' SQL Injection
CVE-2008-1559webappsphp
SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Aperto Blog 0.1.1 - Local File Inclusion / SQL Injection
CVE-2008-5775webappsphp
SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
CadeNix - SQL Injection
CVE-2008-5777webappsphp
SQL injection vulnerability in index.php in CadeNix allows remote attackers to execute arbitrary SQL commands via the ci
23RIESGO
abrir
Referência
CVE-2018-11409
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RIESGO
abrir
página 1 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.