Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
22.492 exploits
Referência
CVE-2026-7098
Tenda F456 httpd DhcpListClient fromDhcpListClient buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7097
Tenda F456 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7096
Tenda HG3 formgponConf os command injection
41RIESGO
abrir
Referência
CVE-2026-7095
code-projects Employee Management System edit.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-7094
ShadowCloneLabs GlutamateMCPServers puppeteer_navigate index.ts server-side request forgery
33RIESGO
abrir
ReferênciaVexDay Proof
Microsoft HTML Workshop 4.74 - Universal Buffer Overflow
CVE-2009-0133localwindows
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RIESGO
abrir
Referência
CVE-2020-28949
CVE-2020-28949HIGHbajo ataque
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper
100RIESGO
abrir
ReferênciaVexDay Proof
AAA EasyGrid ActiveX 3.51 - Remote File Overwrite
CVE-2009-0134remotewindows
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX
23RIESGO
abrir
Referência
CVE-2012-6529
Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir
ReferênciaVexDay Proof
ProjectCMS 1.0b - 'index.php?sn' SQL Injection
CVE-2009-1500webappsphp
SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2017-14496
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-su
35RIESGO
abrir
ReferênciaVexDay Proof
Microsoft GDI Plugin - '.png' Infinite Loop Denial of Service (PoC)
CVE-2009-1511doswindows
GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file tha
28RIESGO
abrir
ReferênciaVexDay Proof
pecio CMS 1.1.5 - 'index.php?language' Local File Inclusion
CVE-2009-1519webappsphp
Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a
23RIESGO
abrir
Referência
CVE-2019-12181
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir
Referência
CVE-2015-2295
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RIESGO
abrir
Referência
CVE-2015-2295
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RIESGO
abrir
Referência
CVE-2013-6194
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RIESGO
abrir
Referência
CVE-2015-8351
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
Referência
CVE-2015-8351
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow
CVE-2006-6251localwindows
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RIESGO
abrir
ReferênciaVexDay Proof
Aigaion 1.3.3 - 'topic topic_id' SQL Injection
CVE-2007-3683webappsphp
SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
Referência
CVE-2019-0211
CVE-2019-0211HIGHbajo ataque
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RIESGO
abrir
Referência
CVE-2019-0211
CVE-2019-0211HIGHbajo ataque
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RIESGO
abrir
Referência
CVE-2019-0211
CVE-2019-0211HIGHbajo ataque
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RIESGO
abrir
Referência
CVE-2019-0211
CVE-2019-0211HIGHbajo ataque
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RIESGO
abrir
Referência
CVE-2014-5519
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a dev
50RIESGO
abrir
Referência
CVE-2014-5519
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a dev
50RIESGO
abrir
Referência
CVE-2021-27877
CVE-2021-27877HIGHbajo ataqueransomware
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RIESGO
abrir
ReferênciaVexDay Proof
ABC Advertise 1.0 - Admin Password Disclosure
CVE-2009-1550webappsphp
Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to
23RIESGO
abrir
Referência
CVE-2016-7203
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
35RIESGO
abrir
anteriorpágina 518 / 750siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.