Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
22.175 exploits
Referência
CVE-2020-3956
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4
28RIESGO
abrir
ReferênciaVexDay Proof
Hospital Management System 4.0 - 'searchdata' SQL Injection
CVE-2020-5192webappsphp
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages an
43RIESGO
abrir
Referência
CVE-2020-6627
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS comman
53RIESGO
abrir
Referência
CVE-2020-6857
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT
23RIESGO
abrir
Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RIESGO
abrir
Referência
CVE-2020-7246
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir
Referência
WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
CVE-2020-8819webappsphp
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in
23RIESGO
abrir
Referência
CVE-2020-9374
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit
35RIESGO
abrir
Referência
CVE-2020-9496
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
Referência
CVE-2026-14820
Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
33RIESGO
abrir
Referência
CVE-2021-21972
CVE-2021-21972CRITICALbajo ataqueransomware
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
Referência
CVE-2015-2462
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RIESGO
abrir
Referência
CVE-2015-2464
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RIESGO
abrir
Referência
CVE-2015-2470
Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 201
28RIESGO
abrir
Referência
CVE-2015-2482
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 an
35RIESGO
abrir
Referência
CVE-2015-2510
Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 S
35RIESGO
abrir
Referência
CVE-2021-24145
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RIESGO
abrir
Referência
CVE-2021-24276
Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
43RIESGO
abrir
Referência
CVE-2021-24499
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RIESGO
abrir
Referência
CVE-2021-24563
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RIESGO
abrir
Referência
CVE-2026-12979
FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer
33RIESGO
abrir
Referência
CVE-2026-40501
Cherry Studio RCE via SearchService nodeIntegration Misconfiguration
41RIESGO
abrir
Referência
CVE-2026-58658
GPUStack Unauthenticated Information Disclosure via Worker Endpoints
41RIESGO
abrir
Referência
CVE-2026-11580
Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
33RIESGO
abrir
Referência
CVE-2026-15693
Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow
41RIESGO
abrir
Referência
CVE-2021-26599
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
43RIESGO
abrir
Referência
CVE-2015-2825
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPres
28RIESGO
abrir
Referência
CVE-2015-2842
Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAu
28RIESGO
abrir
Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RIESGO
abrir
Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RIESGO
abrir
anteriorpágina 396 / 740siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.