Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.692 exploits
Referência
CVE-2026-14621
FederatedAI FATE OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.initEggroll wrong session
28RIESGO
abrir ↗Referência
CVE-2026-10820
ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR
41RIESGO
abrir ↗Referência
CVE-2026-9299
omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption
33RIESGO
abrir ↗Referência
CVE-2026-9296
Edimax BR-6428NS POST Request formWlanM system command injection
33RIESGO
abrir ↗Referência
CVE-2026-9294
Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow
41RIESGO
abrir ↗Referência
CVE-2022-1388
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗Referência
CVE-2022-1388
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗Referência
CVE-2022-26986
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RIESGO
abrir ↗Referência
CVE-2022-27412
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
23RIESGO
abrir ↗Referência
CVE-2022-28117
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap
43RIESGO
abrir ↗Referência
CVE-2022-30519
XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary c
33RIESGO
abrir ↗Referência
CVE-2022-45030
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may
41RIESGO
abrir ↗Referência
CVE-2022-45297
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.
48RIESGO
abrir ↗Referência
CVE-2022-45701
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RIESGO
abrir ↗Referência
CVE-2022-47076
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RIESGO
abrir ↗Referência
CVE-2022-47636
A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open
23RIESGO
abrir ↗Referência
CVE-2022-48197
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RIESGO
abrir ↗Referência
CVE-2023-0493
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RIESGO
abrir ↗Referência
CVE-2023-0527
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RIESGO
abrir ↗Referência
CVE-2023-0669
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.