Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.301 exploits
Referência
CVE-2026-7443
BurtTheCoder mcp-dnstwist MCP index.ts fuzz_domain os command injection
33RIESGO
abrir
Referência
CVE-2012-1465
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RIESGO
abrir
Referência
CVE-2026-7420
UTT HiPER 1250GW ConfigAdvideo strcpy buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7419
UTT HiPER 1250GW formTaskEdit_ap strcpy buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7418
UTT HiPER 1250GW NTP strcpy buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7417
Algovate xhs-mcp MCP mcp.server.ts xhs_publish_content server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-7416
PolarVista xcode-mcp-server MCP index.ts run_tests os command injection
33RIESGO
abrir
Referência
CVE-2026-7410
SourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injection
33RIESGO
abrir
Referência
CVE-2026-7409
SourceCodester Pizzafy Ecommerce System ajax.php save_user sql injection
33RIESGO
abrir
Referência
CVE-2026-6983
pagekit download server-side request forgery
33RIESGO
abrir
Referência
CVE-2010-5195
Untrusted search path vulnerability in Roxio MyDVD 9 allows local users to gain privileges via a Trojan horse HomeUtils9
23RIESGO
abrir
Referência
CVE-2012-1900
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2012-1900
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2026-34414
Xerte Online Toolkits Path Traversal via connector.php
56RIESGO
abrir
Referência
CVE-2026-41459
Xerte Online Toolkits Path Disclosure via /setup
48RIESGO
abrir
Referência
CVE-2026-41468
Beghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection
48RIESGO
abrir
Referência
CVE-2012-2095
The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configur
23RIESGO
abrir
Referência
CVE-2018-16252
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RIESGO
abrir
ReferênciaVexDay Proof
TinyIdentD 2.2 - Remote Buffer Overflow
CVE-2007-2711remotewindows
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RIESGO
abrir
ReferênciaVexDay Proof
NewzCrawler 1.8 - invalid string Remote Denial of Service
CVE-2007-2722doswindows
Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instabili
23RIESGO
abrir
Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
Referência
CVE-2026-41468
Beghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection
48RIESGO
abrir
Referência
CVE-2026-41469
Beghelli Sicuro24 SicuroWeb Missing Content Security Policy
33RIESGO
abrir
Referência
CVE-2026-6564
EMQ EMQX Enterprise Session Handling improper authorization
33RIESGO
abrir
Referência
CVE-2026-41469
Beghelli Sicuro24 SicuroWeb Missing Content Security Policy
33RIESGO
abrir
Referência
CVE-2026-3254
Improper Restriction of Rendered UI Layers or Frames in GitLab
28RIESGO
abrir
Referência
CVE-2026-6497
prasathmani TinyFileManager File Upload filemanager.php server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-6496
prasathmani TinyFileManager POST Parameter filemanager.php path traversal
33RIESGO
abrir
Referência
CVE-2026-6493
lukevella rallly Reset Password reset-password-form.tsx cross site scripting
33RIESGO
abrir
Referência
CVE-2025-65135
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin
48RIESGO
abrir
anteriorpágina 448 / 744siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.