Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.299exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2018-17776
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users
23RIESGO
abrir
Referência
CVE-2026-10152
TaleLin lin-cms-spring-boot book Endpoint BookController.java access control
33RIESGO
abrir
Referência
CVE-2026-10127
Edimax BR-6478AC POST Request formStaDrvSetup command injection
33RIESGO
abrir
Referência
CVE-2026-6000
code-projects Online Library Management System SQL Database Backup File library.sql information disclosure
33RIESGO
abrir
Referência
CVE-2026-5998
zhayujie chatgpt-on-wechat CowAgent API Memory Content Endpoint service.py dispatch path traversal
33RIESGO
abrir
Referência
CVE-2026-5997
Totolink A7100RU CGI cstecgi.cgi setLoginPasswordCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-5994
Totolink A7100RU CGI cstecgi.cgi setTelnetCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-5993
Totolink A7100RU CGI cstecgi.cgi setWiFiGuestCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-5991
Tenda F451 WrlExtraSet formWrlExtraSet stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5990
Tenda F451 SafeEmailFilter fromSafeEmailFilter stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5989
Tenda F451 RouteStatic fromRouteStatic stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5988
Tenda F451 AdvSetWrlsafeset formWrlsafeset stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5987
Sanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engine
33RIESGO
abrir
Referência
CVE-2026-5986
Zod jsVideoUrlParser util.js getTime redos
33RIESGO
abrir
Referência
CVE-2026-5985
code-projects Simple IT Discussion Forum crud.php sql injection
33RIESGO
abrir
Referência
CVE-2018-18419
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filen
23RIESGO
abrir
Referência
CVE-2026-5453
Rico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded key
33RIESGO
abrir
Referência
CVE-2026-5452
UCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key
33RIESGO
abrir
Referência
CVE-2026-5420
Shinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded key
28RIESGO
abrir
Referência
CVE-2026-5417
Dataease SQLbot Elasticsearch es_engine.py get_es_data_by_http server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-5414
Newgen OmniDocs WebApiRequestRedirection resource injection
33RIESGO
abrir
Referência
CVE-2026-5413
Newgen OmniDocs GetWebApiConfiguration information disclosure
33RIESGO
abrir
Referência
CVE-2026-5370
krayin laravel-crm Activities Module/Notes inbox.spec.ts composeMail cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5368
projectworlds Car Rental Project Parameter login.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5360
Free5GC aper type confusion
33RIESGO
abrir
Referência
CVE-2026-5355
Trendnet TEW-657BRM setup.cgi vpn_drop os command injection
33RIESGO
abrir
Referência
CVE-2026-5354
Trendnet TEW-657BRM setup.cgi vpn_connect os command injection
33RIESGO
abrir
Referência
CVE-2026-5353
Trendnet TEW-657BRM setup.cgi ping_test os command injection
33RIESGO
abrir
Referência
CVE-2026-5352
Trendnet TEW-657BRM setup.cgi edit os command injection
33RIESGO
abrir
Referência
CVE-2026-5351
Trendnet TEW-657BRM setup.cgi add_wps_client os command injection
33RIESGO
abrir
anteriorpágina 444 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.