Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8755Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência
CVE-2026-7248
D-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow
48RIESGO
abrir ↗Referência
CVE-2026-7247
D-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-7244
Totolink A8000RU CGI cstecgi.cgi setWiFiEasyGuestCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7243
Totolink A8000RU CGI cstecgi.cgi setRadvdCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2025-10539
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
33RIESGO
abrir ↗Referência
CVE-2026-7241
Totolink A8000RU CGI cstecgi.cgi setWiFiBasicCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7240
Totolink A8000RU CGI cstecgi.cgi setVpnAccountCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7227
SourceCodester Pizzafy Ecommerce System ajax.php login sql injection
33RIESGO
abrir ↗Referência
CVE-2012-0393
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which
35RIESGO
abrir ↗Referência
CVE-2012-0394
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RIESGO
abrir ↗Referência
CVE-2012-0394
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RIESGO
abrir ↗Referência
CVE-2020-37220
Huawei HG630 V2 Router Authentication Bypass via Serial Number
41RIESGO
abrir ↗Referência
CVE-2020-37174
WOOF / Products Filter Professional for WooCommerce 1.2.3 Persistent XSS
33RIESGO
abrir ↗Referência
CVE-2009-4197
rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the au
23RIESGO
abrir ↗Referência
CVE-2014-3792
Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote at
23RIESGO
abrir ↗Referência
Sphider Search Engine - Multiple Vulnerabilities
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
28RIESGO
abrir ↗Referência
CVE-2014-5115
Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname
23RIESGO
abrir ↗Referência
CVE-2010-0249
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and S
100RIESGO
abrir ↗Referência
CVE-2012-1208
Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other
23RIESGO
abrir ↗Referência
CVE-2012-1213
Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6
23RIESGO
abrir ↗Referência
CVE-2012-1217
Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Referência
CVE-2026-19246
HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-19230
SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-19207
PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.