Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.131VulnCheck XDB 8635Nuclei 4274Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.266 exploits
Referência
CVE-2026-6573
PHPEMS Instant Exam Creation exams.master.php temppage server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-6572
Collabora KodExplorer fileUpload Endpoint share.class.php improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-6571
kodcloud KodExplorer systemRole.class.php roleGroupAction authorization
33RIESGO
abrir ↗Referência
CVE-2026-6570
kodcloud KodExplorer systemMember.class.php initInstall authorization
33RIESGO
abrir ↗Referência
CVE-2026-6568
kodcloud KodExplorer Public Share share.class.php initShareOld path traversal
33RIESGO
abrir ↗Referência
CVE-2026-6125
Dromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection
33RIESGO
abrir ↗Referência
CVE-2018-13832
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RIESGO
abrir ↗Referência
CVE-2026-8031
PicoTronica e-Clinic Healthcare System ECHS API Endpoint patient-records missing authentication
33RIESGO
abrir ↗Referência
CVE-2026-8028
FlowiseAI Flowise Endpoint account.service.ts verify information disclosure
33RIESGO
abrir ↗Referência
CVE-2026-7854
D-Link DI-8100 POST Parameter url_rule.asp url_rule_asp buffer overflow
48RIESGO
abrir ↗Referência
CVE-2012-0982
SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attacke
23RIESGO
abrir ↗Referência
CVE-2026-15474
Eleveo Call Recording Software audio.jsp improper authorization
33RIESGO
abrir ↗Referência
CVE-2018-14064
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RIESGO
abrir ↗Referência
CVE-2018-14328
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RIESGO
abrir ↗Referência
CVE-2018-14485
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
28RIESGO
abrir ↗Referência
CVE-2018-14575
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CS
23RIESGO
abrir ↗Referência✓ VexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RIESGO
abrir ↗Referência
CVE-2026-7686
eyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access control
33RIESGO
abrir ↗Referência
CVE-2026-7680
jsbroks COCO Annotator Data Endpoint datasets.py path traversal
33RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - GDI+ '.ICO' File Remote Denial of Service
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of
28RIESGO
abrir ↗Referência
CVE-2026-10185
SourceCodester Hospitals Patient Records Management System Users.php save sql injection
33RIESGO
abrir ↗Referência
CVE-2026-10184
SourceCodester Hospitals Patient Records Management System Users.php delete sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
USP FOSS Distribution 1.01 - 'dnld' Remote File Disclosure
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbi
23RIESGO
abrir ↗Referência
CVE-2026-10169
OUSL-GROUP-BrinaryBrains School Student Management System Forgot Password Endpoint Login.php ajax_forgot_password password recovery
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.