Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.301 exploits
Referência
CVE-2026-12773
BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
33RIESGO
abrir ↗Referência
CVE-2026-12772
BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration
33RIESGO
abrir ↗Referência
CVE-2026-8251
Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
33RIESGO
abrir ↗Referência✓ VexDay Proof
phpAuction GPL Enhanced 2.51 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PH
35RIESGO
abrir ↗Referência
CVE-2011-1099
Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) re
23RIESGO
abrir ↗Referência
CVE-2011-1496
tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a f
23RIESGO
abrir ↗Referência
CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir ↗Referência
CVE-2019-0731
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir ↗Referência
CVE-2019-0796
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir ↗Referência
CVE-2011-1565
Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphica
50RIESGO
abrir ↗Referência
CVE-2026-7200
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-7199
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7194
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7179
OSPG binwalk WinCE Extraction Plugin winceextract.py read_null_terminated_string path traversal
33RIESGO
abrir ↗Referência
CVE-2026-7178
ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-7177
ChatGPTNextWeb NextChat route.ts proxyHandler server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-7159
douinc mkdocs-mcp-plugin server.py list_documents path traversal
33RIESGO
abrir ↗Referência
CVE-2026-7158
dmitryglhf mcp-url-downloader server.py _validate_url_safe server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-7157
disler aider-mcp-server aider_ai_code server.py command injection
33RIESGO
abrir ↗Referência
CVE-2026-7156
Totolink A8000RU CGI cstecgi.cgi CsteSystem os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7155
Totolink A8000RU CGI cstecgi.cgi setLoginPasswordCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7154
Totolink A8000RU CGI cstecgi.cgi setAdvancedInfoShow os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7153
Totolink A8000RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7152
Totolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.