Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.332 exploits
Referência
CVE-2026-13502
antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou
28RIESGO
abrir ↗Referência
CVE-2021-47985
Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
41RIESGO
abrir ↗Referência
CVE-2020-37254
Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
41RIESGO
abrir ↗Referência
CVE-2020-37253
Winstep 18.06.0096 Unquoted Service Path Privilege Escalation
41RIESGO
abrir ↗Referência
CVE-2019-25747
Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation
41RIESGO
abrir ↗Referência
CVE-2026-34102
Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info_get.php
48RIESGO
abrir ↗Referência
CVE-2026-58454
JAIOTlink C492A-W6 4.8.30.57701411 RCE via /Anyka/config Endpoint
41RIESGO
abrir ↗Referência
CVE-2026-13560
Edimax EW-7478APC POST Request formAccept os command injection
33RIESGO
abrir ↗Referência
CVE-2026-13558
CodeAstro Complaint Management System Report addreport cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-13557
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-13556
itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-13555
itsourcecode Online Hotel Management System controller.php add sql injection
33RIESGO
abrir ↗Referência
CVE-2026-53264
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RIESGO
abrir ↗Referência
CVE-2026-9529
GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference
33RIESGO
abrir ↗Referência
CVE-2026-9526
itsourcecode Electronic Judging System edit_team.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9525
itsourcecode Electronic Judging System edit_judge.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9521
fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input
33RIESGO
abrir ↗Referência
CVE-2026-9504
GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds
33RIESGO
abrir ↗Referência
CVE-2018-25361
Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
41RIESGO
abrir ↗Referência
CVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.