Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.332 exploits
Referência
CVE-2026-13590
seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2026-13589
seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2026-34112
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
48RIESGO
abrir ↗Referência
CVE-2026-13588
seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2026-13587
seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2018-9106
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio
23RIESGO
abrir ↗Referência
CVE-2026-10877
SourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-10876
SourceCodester Ship Ferry Ticket Reservation System admin improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-25551
Seagull Software BarTender Deserialization Privilege Escalation via .NET Remoting Service
41RIESGO
abrir ↗Referência
CVE-2018-9237
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
23RIESGO
abrir ↗Referência
CVE-2026-10175
Aider-AI Aider Architect Mode auth.py editor_coder.run code injection
33RIESGO
abrir ↗Referência
CVE-2026-10172
Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2019-0541
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E
83RIESGO
abrir ↗Referência
CVE-2026-11312
bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
33RIESGO
abrir ↗Referência
CVE-2026-9544
Shenzhen Sixun Software Sixun Shanghui Group Business Management System PayConfig sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9543
Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-10783
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
28RIESGO
abrir ↗Referência
CVE-2026-10722
cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
33RIESGO
abrir ↗Referência
CVE-2026-10704
SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection
33RIESGO
abrir ↗Referência
CVE-2026-10703
EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after free
33RIESGO
abrir ↗Referência
CVE-2026-10692
johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.