Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
23.022 exploits
Referência
CVE-2026-19897
mangroup dtale Login Endpoint auth.py login excessive authentication
33RIESGO
abrir
Referência
CVE-2026-19896
mangroup dtale Flask Session Cookie app.py build_secret_key random values
33RIESGO
abrir
Referência
CVE-2026-19895
opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive authentication
33RIESGO
abrir
Referência
CVE-2023-0777
Authentication Bypass by Primary Weakness in modoboa/modoboa
61RIESGO
abrir
Referência
CVE-2019-13494
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long var
23RIESGO
abrir
Referência
CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
Referência
CVE-2026-7732
code-projects BloodBank Managing System request_blood.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RIESGO
abrir
Referência
CVE-2026-18216
Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
33RIESGO
abrir
Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RIESGO
abrir
Referência
CVE-2026-16611
Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
41RIESGO
abrir
Referência
CVE-2026-16541
Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints
33RIESGO
abrir
Referência
CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
Referência
CVE-2025-61884
CVE-2025-61884HIGHbajo ataqueransomware
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RIESGO
abrir
Referência
CVE-2026-16007
Authenticated SQL Injection in AppFlowy
41RIESGO
abrir
Referência
CVE-2026-19834
Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization
33RIESGO
abrir
Referência
CVE-2026-19829
648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal
33RIESGO
abrir
Referência
CVE-2021-3378
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RIESGO
abrir
Referência
CVE-2021-3378
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RIESGO
abrir
Referência
CVE-2026-19828
648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal
33RIESGO
abrir
Referência
CVE-2026-19827
alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal
33RIESGO
abrir
Referência
CVE-2026-19826
alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization
33RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.4.1 < 9.4.2 - Remote DNS Cache Poisoning (Metasploit)
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
Referência
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
CVE-2019-13605webappslinux
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in
28RIESGO
abrir
Referência
CVE-2023-0904
SourceCodester Employee Task Management System task-details.php sql injection
33RIESGO
abrir
Referência
CVE-2008-5970
SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to exe
23RIESGO
abrir
Referência47
Unauthenticated RCE on CraftCMS when PHP `register_argc_argv` config setting is enabled
CVE-2024-56145CRITICALbajo ataque
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
Referência
CVE-2016-7288
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.