Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2016-20073
Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php
41RIESGO
abrir
Referência
CVE-2017-20262
Joomla! Component Ajax Quiz 1.8 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20257
Joomla! Component Quiz Deluxe 3.7.4 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20256
Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
41RIESGO
abrir
Referência
CVE-2017-20255
Joomla! Component JB Visa 1.0 SQL Injection via visatype
41RIESGO
abrir
Referência
CVE-2017-20254
Joomla! Component User Bench 1.0 SQL Injection via userid
41RIESGO
abrir
Referência
CVE-2017-20253
Joomla! Component My Projects 2.0 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20252
Joomla NextGen Editor 2.1.0 SQL Injection via plname Parameter
41RIESGO
abrir
Referência
CVE-2023-54353
Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20071
WordPress 404 Redirection Manager Plugin 1.0 SQL Injection
41RIESGO
abrir
Referência
CVE-2016-20070
WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS
33RIESGO
abrir
Referência
CVE-2026-10181
TRENDnet TEW-432BRP formSysCmd stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-11333
tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-50232
Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags
33RIESGO
abrir
Referência
CVE-2018-9059
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir
Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RIESGO
abrir
Referência
CVE-2018-9155
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RIESGO
abrir
Referência
CVE-2026-49130
Music Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxx
33RIESGO
abrir
Referência
CVE-2026-49129
Music Player Daemon < 0.24.11 SSRF via CurlInputPlugin
33RIESGO
abrir
Referência
CVE-2026-49128
Music Player Daemon < 0.24.11 Path Traversal via LocalStorage URI Handling
41RIESGO
abrir
Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
Referência
CVE-2026-11554
TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation
33RIESGO
abrir
Referência
CVE-2026-11517
UTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow
41RIESGO
abrir
Referência
CVE-2026-11512
itsourcecode Hospital Management System billing.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-11495
CodeAstro Ingredients Stock Management System add_stock.php sql injection
33RIESGO
abrir
Referência
CVE-2026-11494
TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation
33RIESGO
abrir
Referência
CVE-2026-11493
Tenda AC15 Samba smb.conf weak password
28RIESGO
abrir
Referência
CVE-2026-11492
D-Link DIR-823G vsftpd vsftpd.conf least privilege violation
33RIESGO
abrir
Referência
CVE-2026-11491
CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting
33RIESGO
abrir
Referência
CVE-2026-11489
code-projects Online Music Site AdminDeleteAlbum.php sql injection
33RIESGO
abrir
anteriorpágina 472 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.