Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2024-14032
Twitch Studio LauncherHelper XPC Missing Authorization to Root File Write
41RIESGO
abrir
Referência
CVE-2026-5666
code-projects Online FIR System SQL Database Backup File complaints.sql sensitive information
33RIESGO
abrir
Referência
CVE-2026-5665
code-projects Online FIR System Login checklogin.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5661
Free5GC NGSetupRequest denial of service
33RIESGO
abrir
Referência
CVE-2026-5660
itsourcecode Construction Management System Parameter borrowed_equip.php sql injection
33RIESGO
abrir
Referência
CVE-2018-25240
Watchr 1.1.0.0 Denial of Service via Search
33RIESGO
abrir
Referência
CVE-2018-25239
Smart VPN 1.1.3.0 Denial of Service via Search
33RIESGO
abrir
Referência
CVE-2018-25238
VSCO 1.1.1.0 Denial of Service via Search
33RIESGO
abrir
Referência
CVE-2016-20061
sheed AntiVirus 2.3 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20060
Hotspot Shield 6.0.3 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20059
IObit Malware Fighter 4.3.1 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20058
Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20057
NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20052
Snews CMS 1.7 Unrestricted File Upload via snews_files
48RIESGO
abrir
Referência
CVE-2016-20051
Snews CMS 1.7 Cross-Site Request Forgery via changeup
33RIESGO
abrir
Referência
CVE-2016-20050
NetSchedScan 1.0 Buffer Overflow Denial of Service
33RIESGO
abrir
Referência
CVE-2026-5240
code-projects BloodBank Managing System admin_state.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5238
itsourcecode Payroll Management System Parameter view_employee.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5237
itsourcecode Payroll Management System Parameter manage_user.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5236
Axiomatic Bento4 DSI v1 Ap4Dac4Atom.cpp SkipBits heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-5235
Axiomatic Bento4 MP4 File Ap4Dac4Atom.cpp ReadCache heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-5215
D-Link DNS-1550-04 network_mgr.cgi cgi_get_ipv6 access control
33RIESGO
abrir
Referência
CVE-2026-5214
D-Link DNS-1550-04 account_mgr.cgi cgi_addgroup_get_group_quota_minsize stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5213
D-Link DNS-1550-04 account_mgr.cgi cgi_adduser_to_session stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5212
D-Link DNS-1550-04 webdav_mgr.cgi Webdav_Upload_File stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5211
D-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Del stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5210
SourceCodester Leave Application System file inclusion
33RIESGO
abrir
Referência
CVE-2026-5209
SourceCodester Leave Application System User Management cross site scripting
33RIESGO
abrir
Referência
CVE-2026-32113
Discourse: Open redirect via `sso_destination_url` cookie in `enter`
33RIESGO
abrir
Referência
CVE-2026-5206
code-projects Simple Gym Management System Payment sql injection
33RIESGO
abrir
anteriorpágina 440 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.