Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2026-6491
libvips nip2 vips7compat.c im_minpos_vec heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-6490
QueryMine sms GET Request Parameter deletecourse.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6489
QueryMine sms Background Management addteacher.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-6488
QueryMine sms GET Request Parameter editcourse.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6487
Qihui jtbc5 CMS Code Endpoint manage.php path traversal
33RIESGO
abrir
Referência
CVE-2026-6486
classroombookings User Display Name layout.php read cross site scripting
33RIESGO
abrir
Referência
CVE-2026-6483
Wavlink WL-WN530H4 internet.cgi snprintf os command injection
46RIESGO
abrir
Referência
CVE-2026-6148
code-projects Vehicle Showroom Management System MonthTotalReportUpdateFunction.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6140
Totolink A7100RU CGI cstecgi.cgi UploadFirmwareFile os command injection
48RIESGO
abrir
Referência
CVE-2026-6139
Totolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection
48RIESGO
abrir
Referência
CVE-2026-6138
Totolink A7100RU CGI cstecgi.cgi setAccessDeviceCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-6129
zhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication
33RIESGO
abrir
Referência
CVE-2019-25712
BlueAuditor 1.7.2.0 Buffer Overflow Denial of Service via Registration Key
33RIESGO
abrir
Referência
CVE-2019-25711
SpotFTP Password Recover 2.4.2 Denial of Service via Name Field
33RIESGO
abrir
Referência
CVE-2019-25710
Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter
41RIESGO
abrir
Referência
CVE-2019-25709
CF Image Hosting Script 1.6.5 Unauthorized Database Access
48RIESGO
abrir
Referência
CVE-2019-25708
Heatmiser Wifi Thermostat 1.7 Cross-Site Request Forgery
33RIESGO
abrir
Referência
CVE-2019-25705
Echo Mirage 3.1 Stack Buffer Overflow via Rules Action Field
41RIESGO
abrir
Referência
CVE-2019-25703
ImpressCMS 1.3.11 SQL Injection via bid Parameter
41RIESGO
abrir
Referência
CVE-2019-25701
Easy Video to iPod Converter 1.6.20 Local Buffer Overflow SEH
41RIESGO
abrir
Referência
CVE-2019-25697
CMSsite 1.0 SQL Injection via category.php
41RIESGO
abrir
Referência
CVE-2019-25695
R 3.4.4 Local Buffer Overflow Windows XP SP3
41RIESGO
abrir
Referência
CVE-2019-25693
ResourceSpace 8.6 SQL Injection via collection_edit.php
41RIESGO
abrir
Referência
CVE-2019-25691
Faleemi Desktop Software 1.8 Local Buffer Overflow SEH DEP Bypass
41RIESGO
abrir
Referência
CVE-2019-25689
HTML5 Video Player 1.2.5 Local Buffer Overflow Non-SEH
41RIESGO
abrir
Referência
CVE-2018-25258
RGui 3.5.0 Local Buffer Overflow SEH DEP Bypass
41RIESGO
abrir
Referência
CVE-2018-25257
Adianti Framework 5.5.0 and 5.6.0 SQL Injection via Profile
41RIESGO
abrir
Referência
CVE-2017-20239
MDwiki Cross-Site Scripting via Location Hash Parameter
33RIESGO
abrir
Referência
CVE-2026-6126
zhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authentication
33RIESGO
abrir
Referência
CVE-2010-4794
Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.