Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.429 exploits
Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RIESGO
abrir
Referência
CVE-2018-9155
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RIESGO
abrir
Referência
CVE-2026-49130
Music Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxx
33RIESGO
abrir
Referência
CVE-2026-49129
Music Player Daemon < 0.24.11 SSRF via CurlInputPlugin
33RIESGO
abrir
Referência
CVE-2026-49128
Music Player Daemon < 0.24.11 Path Traversal via LocalStorage URI Handling
41RIESGO
abrir
Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
Referência
CVE-2026-11554
TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation
33RIESGO
abrir
Referência
CVE-2026-11517
UTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow
41RIESGO
abrir
Referência
CVE-2026-11512
itsourcecode Hospital Management System billing.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-11495
CodeAstro Ingredients Stock Management System add_stock.php sql injection
33RIESGO
abrir
Referência
CVE-2026-11494
TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation
33RIESGO
abrir
Referência
CVE-2026-11493
Tenda AC15 Samba smb.conf weak password
28RIESGO
abrir
Referência
CVE-2026-11492
D-Link DIR-823G vsftpd vsftpd.conf least privilege violation
33RIESGO
abrir
Referência
CVE-2026-11491
CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting
33RIESGO
abrir
Referência
CVE-2026-11489
code-projects Online Music Site AdminDeleteAlbum.php sql injection
33RIESGO
abrir
Referência
CVE-2018-9488
In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead
23RIESGO
abrir
Referência
CVE-2018-9515
In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co
23RIESGO
abrir
Referência
CVE-2026-10294
PackageKit API pk-transaction.c g_file_test improper authorization
33RIESGO
abrir
Referência
CVE-2026-10287
SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-10258
itsourcecode Content Management System add_sub_topic.php sql injection
33RIESGO
abrir
Referência
CVE-2026-10253
itsourcecode Online House Rental System manage_payment.php sql injection
33RIESGO
abrir
Referência
CVE-2026-10251
itsourcecode Online House Rental System ajax.php login sql injection
33RIESGO
abrir
Referência
CVE-2026-10250
itsourcecode Online Blood Bank Management System campsdetails.php sql injection
33RIESGO
abrir
Referência
CVE-2018-9857
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RIESGO
abrir
Referência
CVE-2018-9948
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
Referência
CVE-2026-10219
nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection
33RIESGO
abrir
Referência
CVE-2026-10218
nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization
33RIESGO
abrir
Referência
CVE-2026-10217
nextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges management
33RIESGO
abrir
Referência
CVE-2026-10216
unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication
33RIESGO
abrir
Referência
CVE-2026-10215
Dolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAccessToObject improper authorization
33RIESGO
abrir
anteriorpágina 513 / 748siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.