Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.266 exploits
Referência
CVE-2024-14032
Twitch Studio LauncherHelper XPC Missing Authorization to Root File Write
41RIESGO
abrir ↗Referência
CVE-2026-5666
code-projects Online FIR System SQL Database Backup File complaints.sql sensitive information
33RIESGO
abrir ↗Referência
CVE-2026-5665
code-projects Online FIR System Login checklogin.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5660
itsourcecode Construction Management System Parameter borrowed_equip.php sql injection
33RIESGO
abrir ↗Referência
CVE-2018-0971
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir ↗Referência
CVE-2018-1002007
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir ↗Referência
CVE-2026-6592
ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-6589
ComfyUI server.py create_origin_only_middleware cross-site request forgery
33RIESGO
abrir ↗Referência
CVE-2026-6588
serge-chat serge Model API Endpoint model.py delete_model missing authentication
33RIESGO
abrir ↗Referência
CVE-2026-6586
TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization
33RIESGO
abrir ↗Referência
CVE-2026-6585
TransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation authorization
33RIESGO
abrir ↗Referência
CVE-2026-6584
TransformerOptimus SuperAGI User Update Endpoint user.py update_user authorization
33RIESGO
abrir ↗Referência
CVE-2026-6583
TransformerOptimus SuperAGI API Key Management Endpoint api_key.py edit_api_key authorization
33RIESGO
abrir ↗Referência
CVE-2026-6582
TransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authentication
33RIESGO
abrir ↗Referência
CVE-2018-1002008
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir ↗Referência
CVE-2026-6574
osuuu LightPicture API Upload Endpoint lp.sql hard-coded credentials
33RIESGO
abrir ↗Referência
CVE-2026-5811
SourceCodester Online Food Ordering System POST Parameter Actions.php save_product logic error
33RIESGO
abrir ↗Referência
CVE-2026-5810
SourceCodester Sales and Inventory System GET Parameter delete.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-5668
Cyber-III Student-Management-System add%20notice.php cross site scripting
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.