Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.301 exploits
Referência
MCL-Net 4.3.5.8788 - Information Disclosure
A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RIESGO
abrir ↗Referência
CVE-2026-14574
In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec
33RIESGO
abrir ↗Referência
CVE-2026-19006
mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
33RIESGO
abrir ↗Referência
CVE-2026-67623
Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
41RIESGO
abrir ↗Referência
CVE-2026-67623
Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
41RIESGO
abrir ↗Referência
CVE-2026-66747
ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
48RIESGO
abrir ↗Referência
CVE-2026-17515
MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item
33RIESGO
abrir ↗Referência
CVE-2026-16055
Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
41RIESGO
abrir ↗Referência
CVE-2026-18790
Systerel S2OPC DeleteMonitoredItemsRequest state_machine.c out-of-bounds
33RIESGO
abrir ↗Referência
CVE-2026-16056
Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts
33RIESGO
abrir ↗Referência
CVE-2026-16035
miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send
33RIESGO
abrir ↗Referência
CVE-2026-15958
Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX
48RIESGO
abrir ↗Referência
CVE-2026-14939
Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import
33RIESGO
abrir ↗Referência
CVE-2026-14872
Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter
33RIESGO
abrir ↗Referência
CVE-2026-14848
Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkout
33RIESGO
abrir ↗Referência
CVE-2026-14824
Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question
33RIESGO
abrir ↗Referência
CVE-2026-14816
The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam
33RIESGO
abrir ↗Referência
CVE-2026-12698
wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment
33RIESGO
abrir ↗Referência
CVE-2026-11366
MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass
28RIESGO
abrir ↗Referência
CVE-2026-16536
Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id
33RIESGO
abrir ↗Referência
CVE-2026-16623
Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)
41RIESGO
abrir ↗Referência
CVE-2026-16618
ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution
48RIESGO
abrir ↗Referência
CVE-2026-18723
diaowen DWSurvey Survey Status up-survey-status.do improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-18722
diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authorization
33RIESGO
abrir ↗Referência
CVE-2026-18720
kalcaddle kodbox msgWarning Plugin action improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-18686
GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.