Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.301 exploits
Referência
CVE-2026-12270
Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assistant REST Endpoints
33RIESGO
abrir
Referência
CVE-2026-15138
tumf mcp-text-editor text_editor.py _validate_file_path path traversal
33RIESGO
abrir
Referência
CVE-2026-15137
code-projects Interview Management System View.php sql injection
33RIESGO
abrir
Referência
CVE-2026-15135
code-projects Online Food Order System edit_food_items.php sql injection
33RIESGO
abrir
Referência
CVE-2021-30034
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
23RIESGO
abrir
Referência
CVE-2026-34099
Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info.php
48RIESGO
abrir
Referência
CVE-2026-58376
Dolibarr - SQL Injection via sqlfilters Parameter in Multiple REST API List Endpoints
41RIESGO
abrir
Referência
CVE-2026-58375
JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export
41RIESGO
abrir
Referência
CVE-2026-58371
SeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP callback Parameter
28RIESGO
abrir
Referência
CVE-2026-58176
RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints
41RIESGO
abrir
Referência
CVE-2026-13571
SourceCodester Simple Food Ordering System cart.php logic error
33RIESGO
abrir
Referência
CVE-2026-40523
FrontAccounting < 2.4.20 SQL Injection via reporting/rep710.php
41RIESGO
abrir
Referência
CVE-2026-9676
f4 Post Tree < 2.0.5 - Subscriber+ Arbitrary Post Parent/Menu Order Modification
33RIESGO
abrir
Referência
CVE-2026-10083
APCu Manager < 4.5.0 - Unauthenticated Stored XSS via Cache Key Pollution
41RIESGO
abrir
Referência
CVE-2026-13540
GitBucket RepositoryCreationService.scala Git.cloneRepository.setURI server-side request forgery
33RIESGO
abrir
Referência
CVE-2021-30039
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo
23RIESGO
abrir
Referência
CVE-2021-30042
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont
23RIESGO
abrir
Referência
CVE-2021-3018
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
43RIESGO
abrir
Referência
WinWaste.NET 1.0.6183.16475 - Privilege Escalation due Incorrect Access Control
CVE-2021-34110localwindows
WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executa
23RIESGO
abrir
Referência
CVE-2026-10806
mjperpinosa stumasy add_post.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Referência
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Referência
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Referência
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Referência
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Referência
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Referência
CVE-2015-4414
Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player)
43RIESGO
abrir
Referência
CVE-2015-4481
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Win
23RIESGO
abrir
Referência
CVE-2015-4624
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
Referência
CVE-2015-4624
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
anteriorpágina 468 / 744siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.