Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.301 exploits
Referência
CVE-2021-47982
WordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset
33RIESGO
abrir
Referência
CVE-2026-11467
jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal
33RIESGO
abrir
Referência
CVE-2026-11463
USCiLab Cereal Shared Pointer type confusion
33RIESGO
abrir
Referência
CVE-2026-11455
FoundationAgents MetaGPT common.py check_cmd_exists command injection
28RIESGO
abrir
Referência
CVE-2026-19383
saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-15148
WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR
33RIESGO
abrir
Referência
CVE-2026-16265
WP Maps < 4.9.7 - Subscriber+ Denial of Service
33RIESGO
abrir
Referência
CVE-2026-19195
V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control
41RIESGO
abrir
Referência
CVE-2026-19193
Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control
41RIESGO
abrir
Referência
CVE-2026-37171
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one
33RIESGO
abrir
Referência
CVE-2026-70636
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
41RIESGO
abrir
Referência
CVE-2026-67622
Flowise 3.1.4 IDOR in OpenAI Assistants Integration
41RIESGO
abrir
Referência
CVE-2026-67621
Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
41RIESGO
abrir
Referência
CVE-2026-19110
DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting
33RIESGO
abrir
Referência
CVE-2026-19108
MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free
33RIESGO
abrir
Referência
CVE-2026-19071
itsourcecode Hospital Management System viewappointment.php sql injection
33RIESGO
abrir
Referência
CVE-2026-19070
itsourcecode Hospital Management System viewadmin.php sql injection
33RIESGO
abrir
Referência
CVE-2026-19069
itsourcecode Hospital Management System treatmentrecord.php sql injection
33RIESGO
abrir
Referência
CVE-2026-19068
itsourcecode Hospital Management System treatmentdetail.php sql injection
33RIESGO
abrir
Referência
CVE-2026-19067
itsourcecode Hospital Management System treatment.php sql injection
33RIESGO
abrir
Referência
CVE-2025-15674
Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
28RIESGO
abrir
Referência
CVE-2026-16620
WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
41RIESGO
abrir
Referência
CVE-2026-16619
miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
41RIESGO
abrir
Referência
CVE-2026-19062
chiuwingyan house selectall.action sql injection
33RIESGO
abrir
Referência
CVE-2026-16067
Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
33RIESGO
abrir
Referência
CVE-2026-15256
Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
33RIESGO
abrir
Referência
CVE-2026-17032
Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
48RIESGO
abrir
Referência
CVE-2026-13342
Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
33RIESGO
abrir
Referência
CVE-2026-15149
WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
33RIESGO
abrir
Referência
CVE-2026-15208
RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification
33RIESGO
abrir
anteriorpágina 475 / 744siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.