Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2017-8479
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2026-3326
XStore < 9.7.3 - Unauthenticated SQLi
56RIESGO
abrir
Referência
CVE-2026-14843
Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR
33RIESGO
abrir
Referência
CVE-2006-1747
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RIESGO
abrir
Referência
CVE-2005-4696
The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-s
23RIESGO
abrir
ReferênciaVexDay Proof
rgboard 3.0.12 - Remote File Inclusioni / Cross-Site Scripting
CVE-2008-2295webappsphp
Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remot
23RIESGO
abrir
Referência
CVE-2018-10310
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RIESGO
abrir
Referência
CVE-2018-10310
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RIESGO
abrir
Referência
CVE-2014-9311
Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remo
23RIESGO
abrir
Referência
CVE-2018-17428
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio par
23RIESGO
abrir
Referência
CVE-2019-11416
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RIESGO
abrir
Referência
CVE-2019-11416
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RIESGO
abrir
Referência
CVE-2013-4950
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir
Referência
CVE-2010-1270
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2011-5228
Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote att
23RIESGO
abrir
Referência
CVE-2012-2939
Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute
23RIESGO
abrir
Referência
CVE-2026-11530
imvks786 student_management_system Login index.ph sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
CVE-2006-4632webappsphp
Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2015-1422
Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
W3Filer 2.1.3 - Remote Stack Overflow (PoC)
CVE-2007-3548doswindows
Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or
23RIESGO
abrir
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.mpr replay' Local Buffer Overflow
CVE-2007-4140localwindows
Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary c
23RIESGO
abrir
Referência
CVE-2010-5001
SQL injection vulnerability in view.php in esoftpro Online Contact Manager 3.0 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2010-5008
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to
23RIESGO
abrir
Referência
CVE-2010-5009
SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2010-3134
Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to
23RIESGO
abrir
ReferênciaVexDay Proof
68 Classifieds 4.0 - 'category.php' SQL Injection
CVE-2008-2336webappsphp
SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2025-34024
Edimax EW-7438RPn Mini OS Command Injection via mp.asp
48RIESGO
abrir
Referência
CVE-2018-9844
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
23RIESGO
abrir
Referência
CVE-2019-17504
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln
23RIESGO
abrir
Referência
CVE-2021-26078
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before
23RIESGO
abrir
anteriorpágina 623 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.