Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.332 exploits
Referência
CVE-2026-13502
antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou
28RIESGO
abrir
Referência
CVE-2026-13501
antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
33RIESGO
abrir
Referência
CVE-2022-50971
Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2021-47985
Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2020-37254
Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
41RIESGO
abrir
Referência
CVE-2020-37253
Winstep 18.06.0096 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2019-25747
Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2026-34102
Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info_get.php
48RIESGO
abrir
Referência
CVE-2026-58454
JAIOTlink C492A-W6 4.8.30.57701411 RCE via /Anyka/config Endpoint
41RIESGO
abrir
Referência
CVE-2026-13560
Edimax EW-7478APC POST Request formAccept os command injection
33RIESGO
abrir
Referência
CVE-2026-13558
CodeAstro Complaint Management System Report addreport cross site scripting
33RIESGO
abrir
Referência
CVE-2026-13557
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
33RIESGO
abrir
Referência
CVE-2026-13556
itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting
33RIESGO
abrir
Referência
CVE-2026-13555
itsourcecode Online Hotel Management System controller.php add sql injection
33RIESGO
abrir
Referência
CVE-2026-54092
File Browser: DoS Vulnerability on Public Login API
33RIESGO
abrir
Referência
CVE-2026-53264
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RIESGO
abrir
Referência
CVE-2026-9529
GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference
33RIESGO
abrir
Referência
CVE-2026-9526
itsourcecode Electronic Judging System edit_team.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9525
itsourcecode Electronic Judging System edit_judge.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9521
fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input
33RIESGO
abrir
Referência
CVE-2026-9504
GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds
33RIESGO
abrir
Referência
CVE-2018-25367
NASA openVSP 3.16.1 Denial of Service via Buffer Overflow
33RIESGO
abrir
Referência
CVE-2018-25364
Twitter-Clone 1 SQL Injection via search.php
41RIESGO
abrir
Referência
CVE-2018-25363
Twitter-Clone 1 Cross-Site Request Forgery via tweetdel.php
33RIESGO
abrir
Referência
CVE-2018-25362
Twitter-Clone 1 SQL Injection via follow.php
41RIESGO
abrir
Referência
CVE-2018-25361
Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
41RIESGO
abrir
Referência
CVE-2018-25360
AgataSoft Auto PingMaster 1.5 Buffer Overflow SEH
41RIESGO
abrir
Referência
CVE-2026-9463
Edimax EW-7438RPn formLicence stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9461
Edimax EW-7438RPn formRadius stack-based overflow
41RIESGO
abrir
Referência
CVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti
23RIESGO
abrir
anteriorpágina 476 / 745siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.