Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.301 exploits
Referência
CVE-2026-5013
elecV2 elecV2P :key path.join path traversal
33RIESGO
abrir
Referência
CVE-2026-5012
elecV2 elecV2P rpc pm2run os command injection
33RIESGO
abrir
Referência
CVE-2026-5011
elecV2 elecV2P JSON webhook runJSFile code injection
33RIESGO
abrir
Referência
CVE-2026-5007
kazuph mcp-docs-rag add_git_repository/add_text_file index.ts cloneRepository os command injection
33RIESGO
abrir
Referência
CVE-2026-5004
Wavlink WL-WN579X3-C UPNP firewall.cgi sub_4019FC stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5003
PromtEngineer localGPT Web api_server.py handle_index information disclosure
33RIESGO
abrir
Referência
CVE-2026-5002
PromtEngineer localGPT LLM Prompt server.py _route_using_overviews injection
33RIESGO
abrir
Referência
CVE-2026-5001
PromtEngineer localGPT server.py do_POST unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-4999
z-9527 admin isImg Check upload.js uploadFile path traversal
33RIESGO
abrir
Referência
CVE-2026-4998
Sinaptik AI PandasAI Chat Message code_executor.py CodeExecutor.execute code injection
33RIESGO
abrir
Referência
CVE-2026-4997
Sinaptik AI PandasAI sql_sanitizer.py is_sql_query_safe path traversal
33RIESGO
abrir
Referência
CVE-2017-20228
Flat Assembler 1.71.21 Stack-Based Buffer Overflow ROP
41RIESGO
abrir
Referência
CVE-2018-25225
SIPP 3.3 Stack-Based Buffer Overflow via Configuration File
41RIESGO
abrir
Referência
CVE-2018-25224
PMS 0.42 Stack-Based Buffer Overflow via Configuration File
41RIESGO
abrir
Referência
CVE-2018-25223
Crashmail 1.6 Stack-based Buffer Overflow Remote Code Execution
48RIESGO
abrir
Referência
CVE-2018-25222
SC v7.16 Stack-Based Buffer Overflow Remote Code Execution
41RIESGO
abrir
Referência
CVE-2018-25221
EChat Server 3.1 Buffer Overflow via chat.ghp username Parameter
48RIESGO
abrir
Referência
CVE-2018-25220
Bochs 2.6-5 Buffer Overflow Remote Code Execution
48RIESGO
abrir
Referência
CVE-2017-20229
MAWK 1.3.3-17 Stack-Based Buffer Overflow
48RIESGO
abrir
ReferênciaVexDay Proof
Seditio CMS 121 - 'pfs.php' Arbitrary File Upload
CVE-2007-4057webappsphp
Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users
23RIESGO
abrir
Referência
CVE-2018-19135
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RIESGO
abrir
Referência
CVE-2018-19371
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive
23RIESGO
abrir
Referência
CVE-2012-4279
Multiple SQL injection vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
VMware Inc 6.0.0 - CreateProcess Remote Code Execution
CVE-2007-4155remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attac
23RIESGO
abrir
Referência
CVE-2012-4280
Multiple cross-site request forgery (CSRF) vulnerabilities in admin/agenteditor.php in Free Realty 3.1-0.6 allow remote
23RIESGO
abrir
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
CVE-2007-4183webappsphp
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2018-19571
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RIESGO
abrir
Referência
CVE-2018-19752
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
38RIESGO
abrir
Referência
CVE-2010-5285
Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the a
23RIESGO
abrir
Referência
CVE-2018-20469
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to
28RIESGO
abrir
anteriorpágina 452 / 744siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.