Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
CVE-2026-14719
SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management
33RIESGO
abrir
Referência
CVE-2026-14605
RT-Thread ls1c CAN ls1c_can.h recvmsg stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-14604
Open Asset Import Library Assimp PLY Model PlyLoader.cpp ExportToBlob double free
33RIESGO
abrir
Referência
CVE-2026-59098
LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search
41RIESGO
abrir
Referência
CVE-2026-59097
Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets
33RIESGO
abrir
Referência
CVE-2026-59095
LobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl
41RIESGO
abrir
Referência
CVE-2022-29464
CVE-2022-29464CRITICALbajo ataqueransomware
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
Referência
CVE-2026-59094
Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store
41RIESGO
abrir
Referência
CVE-2026-58579
RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name
33RIESGO
abrir
Referência
CVE-2024-58352
Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do
41RIESGO
abrir
Referência
CVE-2022-50973
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
48RIESGO
abrir
Referência
CVE-2022-50973
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
48RIESGO
abrir
Referência
CVE-2022-50973
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
48RIESGO
abrir
Referência
CVE-2026-14440
Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records
41RIESGO
abrir
Referência
CVE-2026-34110
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.php
48RIESGO
abrir
ReferênciaVexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
CVE-2006-1363webappsphp
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
ASP.NET w3wp - COM Components Remote Crash
CVE-2006-1364doswindows
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RIESGO
abrir
ReferênciaVexDay Proof
XHP CMS 0.5 - 'upload' Remote Command Execution
CVE-2006-1371webappsphp
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea Fil
23RIESGO
abrir
ReferênciaVexDay Proof
phpBookingCalendar 1.0c - 'details_view.php' SQL Injection
CVE-2006-1422webappsphp
SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to exec
23RIESGO
abrir
Referência
CVE-2023-22518
CVE-2023-22518CRITICALbajo ataqueransomware
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir
Referência
CVE-2021-1498
CVE-2021-1498CRITICALbajo ataque
Cisco HyperFlex HX Command Injection Vulnerabilities
100RIESGO
abrir
ReferênciaVexDay Proof
SQuery 4.5 - 'libpath' Remote File Inclusion
CVE-2006-1610webappsphp
PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Auton
23RIESGO
abrir
Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RIESGO
abrir
Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RIESGO
abrir
ReferênciaVexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
CVE-2006-1664doslinux
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, a
28RIESGO
abrir
ReferênciaVexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
CVE-2006-1667webappsphp
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gal
23RIESGO
abrir
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1779webappsphp
Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Monster Top List 1.4.2 - 'functions.php?root_path' Remote File Inclusion
CVE-2006-1781webappsphp
PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Sphider 1.3 - 'configset.php' Remote File Inclusion
CVE-2006-1784webappsphp
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disa
23RIESGO
abrir
ReferênciaVexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
CVE-2006-1832webappscgi
sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.
23RIESGO
abrir
anteriorpágina 340 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.