Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.008exploits catalogados
35.919CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2013-3532
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote
23RIESGO
abrir
Referência
CVE-2013-3532
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote
23RIESGO
abrir
Referência
CVE-2013-3537
Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2026-9627
UTT HiPER 1200GW Web Management setSysAdm strcpy buffer overflow
41RIESGO
abrir
Referência
CVE-2025-8730
Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
48RIESGO
abrir
ReferênciaVexDay Proof
Zervit Web Server 0.02 - Remote Buffer Overflow (PoC)
CVE-2009-1353doswindows
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause
23RIESGO
abrir
ReferênciaVexDay Proof
Elecard AVC HD Player - '.XPL' Stack Buffer Overflow (SEH) (PoC)
CVE-2009-1356doswindows
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi
23RIESGO
abrir
Referência
CVE-2011-3496
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell me
28RIESGO
abrir
Referência
CVE-2011-3833
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote
43RIESGO
abrir
Referência
CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Referência
CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Referência
CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
Referência
CVE-2026-9575
itsourcecode Student Transcript Processing System index.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9574
itsourcecode Student Transcript Processing System trans.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9573
itsourcecode Student Transcript Processing System index.php sql injection
33RIESGO
abrir
Referência
CVE-2026-7293
SourceCodester Pizzafy Ecommerce System ajax.php delete_category sql injection
33RIESGO
abrir
Referência
CVE-2025-32432
CVE-2025-32432CRITICALbajo ataque
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
ReferênciaVexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
CVE-2009-1664webappsphp
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords
23RIESGO
abrir
Referência
CVE-2015-1130
CVE-2015-1130HIGHbajo ataque
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir
Referência
CVE-2009-4761
Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir
Referência
CVE-2015-1427
CVE-2015-1427CRITICALbajo ataque
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
Referência
CVE-2026-24061
CVE-2026-24061CRITICALbajo ataque
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
ReferênciaVexDay Proof
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
CVE-2009-2081webappsphp
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir
ReferênciaVexDay Proof
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
CVE-2009-2095webappsphp
PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when regi
23RIESGO
abrir
Referência
CVE-2011-4800
Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and wri
23RIESGO
abrir
Referência
CVE-2022-41040
CVE-2022-41040HIGHbajo ataqueransomware
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
Referência
CVE-2015-1479
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 buil
23RIESGO
abrir
Referência
CVE-2009-2123
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
ReferênciaVexDay Proof
DB Top Sites 1.0 - 'index.php?u' Local File Inclusion
CVE-2009-2110webappsphp
Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attack
23RIESGO
abrir
Referência
CVE-2011-4812
Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web s
23RIESGO
abrir
anteriorpágina 603 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.