Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.298exploits catalogados
35.468CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2018-25288
StyleWriter 1.0 Denial of Service via Pattern Input
33RIESGO
abrir
Referência
CVE-2026-5970
FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection
33RIESGO
abrir
Referência
CVE-2026-5962
Tenda CH22 httpd R7WebsSecurityHandlerfunction path traversal
33RIESGO
abrir
Referência
CVE-2026-5961
code-projects Simple IT Discussion Forum topic-details.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5960
code-projects Patient Record Management System SQL Database Backup File hcpms.sql information disclosure
33RIESGO
abrir
Referência
CVE-2016-20055
IObit Advanced SystemCare 10.0.2 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2010-4838
SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users
23RIESGO
abrir
Referência
CVE-2010-4839
SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to e
23RIESGO
abrir
Referência
CVE-2010-4843
SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2010-4843
SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2010-4847
SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2010-4850
Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Referência
CVE-2018-0710
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RIESGO
abrir
Referência
CVE-2018-0710
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RIESGO
abrir
Referência
CVE-2018-0748
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RIESGO
abrir
Referência
CVE-2018-25287
Drive Power Manager 1.10 Denial of Service via Name Field
33RIESGO
abrir
Referência
CVE-2018-25286
Easy PhotoResQ 1.0 Buffer Overflow Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25285
Fathom 2.4 Denial of Service via Authorization Code Buffer Overflow
33RIESGO
abrir
Referência
CVE-2018-25284
HD Tune Pro 5.70 Denial of Service via Options Dialog
33RIESGO
abrir
Referência
CVE-2018-25283
iSmartViewPro 1.5 Buffer Overflow via SavePath Parameter
41RIESGO
abrir
Referência
CVE-2018-25282
Nmap 7.70 Denial of Service via XML Entity Expansion
33RIESGO
abrir
Referência
CVE-2018-25281
iCash 7.6.5 Denial of Service via Connect to Server
33RIESGO
abrir
Referência
CVE-2018-25280
Infiltrator Network Security Scanner 4.6 Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25279
jiNa OCR Image to Text 1.0 Denial of Service via PNG
33RIESGO
abrir
Referência
CVE-2018-25278
PicaJet FX 2.6.5 Denial of Service via Registration Fields
33RIESGO
abrir
Referência
CVE-2018-0752
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RIESGO
abrir
Referência
CVE-2018-0823
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RIESGO
abrir
Referência
CVE-2026-5806
code-projects Easy Blog Site update.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5805
code-projects Easy Blog Site contact_us.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5803
bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery
33RIESGO
abrir
anteriorpágina 434 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.