Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
Referência
CVE-2026-8781
omec-project amf handler.go RANConfiguration null pointer dereference
33RIESGO
abrir
Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RIESGO
abrir
Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RIESGO
abrir
Referência
CVE-2026-45233
HTMLy CMS 3.1.1 Path Traversal via oldfile Parameter in Autosave
41RIESGO
abrir
Referência
CVE-2026-12807
Edimax BR-6478AC V2 POST Request setWAN command injection
33RIESGO
abrir
Referência
CVE-2019-25763
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass
48RIESGO
abrir
Referência
CVE-2019-25749
Joomla J-CruisePortal 6.0.4 SQL Injection via cruises
41RIESGO
abrir
Referência
CVE-2019-25748
Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels
41RIESGO
abrir
Referência
CVE-2017-20282
Joomla! Component jCart for OpenCart 2.0 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20281
Joomla! Component Extra Search 2.2.8 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20280
Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter
41RIESGO
abrir
Referência
CVE-2017-20279
Joomla Payage 2.05 SQL Injection via aid Parameter
41RIESGO
abrir
Referência
CVE-2017-20278
Joomla JoomRecipe 1.0.3 SQL Injection via category parameter
41RIESGO
abrir
Referência
CVE-2019-12181
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir
Referência
CVE-2019-12477
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcas
43RIESGO
abrir
Referência
CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
Referência
Vim < 8.1.1365 / Neovim < 0.3.6 - Arbitrary Code Execution
CVE-2019-12735locallinux
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RIESGO
abrir
ReferênciaVexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
CVE-2019-12840remotelinux
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
Referência
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
CVE-2019-12922webappsphp
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
28RIESGO
abrir
Referência
CVE-2019-25744
WordPress Popup Builder 3.49 Persistent Cross-Site Scripting
33RIESGO
abrir
Referência
CVE-2019-25743
WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting
33RIESGO
abrir
Referência
CVE-2019-25742
WordPress Theme Zoner Real Estate 4.1.1 Persistent XSS
33RIESGO
abrir
Referência
CVE-2019-25741
Mobatek MobaXterm 12.1 Buffer Overflow via Sessions File
48RIESGO
abrir
Referência
CVE-2019-25740
Joomla com_jsjobs 1.2.6 Arbitrary File Deletion
41RIESGO
abrir
Referência
CVE-2019-25739
GigToDo Freelance Marketplace Script 1.3 Persistent XSS
33RIESGO
abrir
Referência
CVE-2019-25738
WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change
48RIESGO
abrir
Referência
CVE-2019-25737
Live Chat Unlimited 2.8.3 Stored Cross-Site Scripting
33RIESGO
abrir
Referência
CVE-2019-25736
LabF nfsAxe 3.7 Ping Client Buffer Overflow
41RIESGO
abrir
Referência
CVE-2026-10529
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
33RIESGO
abrir
Referência
CVE-2026-10276
hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery
33RIESGO
abrir
anteriorpágina 496 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.