Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
23.022 exploits
Referência
CVE-2016-0049
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RIESGO
abrir
Referência
CVE-2026-19928
OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges management
33RIESGO
abrir
Referência
CVE-2018-14335
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read
38RIESGO
abrir
Referência
CVE-2026-19927
OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-19926
Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection
33RIESGO
abrir
Referência
CVE-2017-1000373
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N
28RIESGO
abrir
Referência
CVE-2011-4713
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arb
23RIESGO
abrir
Referência
CVE-2017-10661
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denia
28RIESGO
abrir
Referência
CVE-2018-8298
CVE-2018-8298HIGHbajo ataque
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RIESGO
abrir
Referência
CVE-2022-20707
Cisco Small Business RV Series Routers Vulnerabilities
85RIESGO
abrir
Referência
CVE-2021-36711
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
28RIESGO
abrir
Referência
CVE-2010-1885
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server
60RIESGO
abrir
ReferênciaVexDay Proof
Dovecot IMAP 1.0.10 < 1.1rc2 - Remote Email Disclosure
CVE-2008-1218remotemultiple
Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs,
23RIESGO
abrir
Referência
CVE-2019-13235
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
23RIESGO
abrir
Referência
CVE-2019-13272
CVE-2019-13272HIGHbajo ataque
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Referência
CVE-2019-13272
CVE-2019-13272HIGHbajo ataque
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Referência
CVE-2011-4808
SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Bloo 1.00 - Multiple SQL Injections
CVE-2008-1313webappsphp
Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
QuickTalk Forum 1.6 - Blind SQL Injection
CVE-2008-1316webappsphp
SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Aperto Blog 0.1.1 - Local File Inclusion / SQL Injection
CVE-2008-5775webappsphp
SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
CadeNix - SQL Injection
CVE-2008-5777webappsphp
SQL injection vulnerability in index.php in CadeNix allows remote attackers to execute arbitrary SQL commands via the ci
23RIESGO
abrir
ReferênciaVexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
CVE-2008-1344webappsphp
Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
EasyGallery 5.0tr - Multiple Vulnerabilities
CVE-2008-1347webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr a
23RIESGO
abrir
ReferênciaVexDay Proof
Fully Modded phpBB - 'kb.php' SQL Injection
CVE-2008-1350webappsphp
SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2018-11409
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RIESGO
abrir
ReferênciaVexDay Proof
iGaming CMS 1.5 - Multiple SQL Injections
CVE-2008-5841webappsphp
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2026-19923
code-projects Online Shopping System checkout_process.php sql injection
33RIESGO
abrir
Referência
CVE-2026-19922
code-projects Online Shopping System checkout.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-19921
code-projects Online Shopping System homeaction.php sql injection
33RIESGO
abrir
Referência
CVE-2022-27925
CVE-2022-27925HIGHbajo ataqueransomware
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir
página 1 / 768siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.