Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
20.023 exploits
Referência
CVE-2012-3448
Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown
23RIESGO
abrir
Referência
CVE-2010-1476
Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote
38RIESGO
abrir
Referência
CVE-2010-1476
Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote
38RIESGO
abrir
Referência
Vtiger CRM 7.1.0 - Remote Code Execution
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the upload
23RIESGO
abrir
Referência
CVE-2016-0862
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
23RIESGO
abrir
Referência
CVE-2016-0862
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
23RIESGO
abrir
Referência
CVE-2018-11523
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
23RIESGO
abrir
Referência
PHP Live! 3.2.1 - 'help.php' Remote File Inclusion
PHP remote file inclusion vulnerability in OSI Codes PHP Live! 3.2.1 and earlier allows remote attackers to execute arbi
28RIESGO
abrir
Referência
CVE-2026-6591
ComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal
33RIESGO
abrir
Referência
CVE-2009-5135
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a req
23RIESGO
abrir
Referência
Xero Portal - 'phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Referência
CVE-2019-12461
Web Port 1.19.1 allows XSS via the /log type parameter.
38RIESGO
abrir
Referência
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow rem
23RIESGO
abrir
Referência
CVE-2018-5723
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
23RIESGO
abrir
Referência
CVE-2018-5723
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
23RIESGO
abrir
Referência
CVE-2021-41878
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RIESGO
abrir
Referência
NetRisk 1.9.7 - Local/Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arb
35RIESGO
abrir
Referência
CVE-2015-5161
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RIESGO
abrir
Referência
CVE-2018-11510
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir
Referência
CVE-2015-5161
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RIESGO
abrir
Referência
CVE-2018-11479
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
38RIESGO
abrir
Referência
CVE-2025-34077
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir
Referência
CVE-2025-34077
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir
Referência
i-doit CMDB 1.11.2 - Remote Code Execution
i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allow
23RIESGO
abrir
Referência
CVE-2015-1130
CVE-2015-1130HIGHbajo ataque
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir
Referência
CVE-2026-6590
ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal
33RIESGO
abrir
Referência
CVE-2013-6231
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
23RIESGO
abrir
Referência
CVE-2022-23626
Insufficient file checks in m1k1o/blog
41RIESGO
abrir
Referência
RSSonate - 'xml2rss.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers
23RIESGO
abrir
Referência
aeDating 4.1 - dir[inc] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attacker
23RIESGO
abrir
anteriorpágina 157 / 668siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.