Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
ReferênciaVexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
CVE-2019-12840remotelinux
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
Referência
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
CVE-2019-12922webappsphp
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
28RIESGO
abrir
Referência
CVE-2019-25744
WordPress Popup Builder 3.49 Persistent Cross-Site Scripting
33RIESGO
abrir
Referência
CVE-2019-25743
WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting
33RIESGO
abrir
Referência
CVE-2019-25742
WordPress Theme Zoner Real Estate 4.1.1 Persistent XSS
33RIESGO
abrir
Referência
CVE-2019-25741
Mobatek MobaXterm 12.1 Buffer Overflow via Sessions File
48RIESGO
abrir
Referência
CVE-2019-25740
Joomla com_jsjobs 1.2.6 Arbitrary File Deletion
41RIESGO
abrir
Referência
CVE-2019-25739
GigToDo Freelance Marketplace Script 1.3 Persistent XSS
33RIESGO
abrir
Referência
CVE-2019-25738
WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change
48RIESGO
abrir
Referência
CVE-2019-25737
Live Chat Unlimited 2.8.3 Stored Cross-Site Scripting
33RIESGO
abrir
Referência
CVE-2019-25736
LabF nfsAxe 3.7 Ping Client Buffer Overflow
41RIESGO
abrir
Referência
CVE-2026-10529
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
33RIESGO
abrir
Referência
CVE-2026-10276
hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-10275
OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow
28RIESGO
abrir
Referência
CVE-2026-10265
itsourcecode Content Management System edit_topic.php sql injection
33RIESGO
abrir
Referência
CVE-2026-10235
CodeAstro Ingredients Stock Management System stock_manager.php sql injection
33RIESGO
abrir
Referência
CVE-2026-10233
Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-bounds
33RIESGO
abrir
Referência
CVE-2025-15686
Open5GS HSS Service fd_msg_sess_get denial of service
33RIESGO
abrir
Referência
CVE-2025-15684
Open5GS CER init.c diam_log_func assertion
33RIESGO
abrir
Referência
CVE-2024-14044
Open5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflow
33RIESGO
abrir
Referência
CVE-2024-14043
Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow
33RIESGO
abrir
Referência
CVE-2019-13235
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
23RIESGO
abrir
Referência
CVE-2019-13272
CVE-2019-13272HIGHbajo ataque
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Referência
CVE-2024-14042
Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow
33RIESGO
abrir
Referência
CVE-2022-50997
Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp
41RIESGO
abrir
Referência
CVE-2016-20097
Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad
41RIESGO
abrir
Referência
CVE-2019-13272
CVE-2019-13272HIGHbajo ataque
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Referência
CVE-2019-13272
CVE-2019-13272HIGHbajo ataque
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Referência
CVE-2019-13272
CVE-2019-13272HIGHbajo ataque
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Referência
CVE-2019-13272
CVE-2019-13272HIGHbajo ataque
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
anteriorpágina 491 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.