Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.332 exploits
Referência
CVE-2026-73030
unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape
41RIESGO
abrir ↗Referência
CVE-2026-72743
SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html
33RIESGO
abrir ↗Referência
CVE-2026-69118
Cachet 2.4.1 Authenticated Server-Side Template Injection RCE
41RIESGO
abrir ↗Referência
CVE-2026-9632
UTT HiPER 1250GW Web Management formGroupConfig strcpy stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-15238
Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR
33RIESGO
abrir ↗Referência
CVE-2026-15237
Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint
33RIESGO
abrir ↗Referência
CVE-2026-14941
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
33RIESGO
abrir ↗Referência
CVE-2026-14860
Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
33RIESGO
abrir ↗Referência
CVE-2026-14206
HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
41RIESGO
abrir ↗Referência
CVE-2026-13701
Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting
33RIESGO
abrir ↗Referência
CVE-2026-13600
AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
41RIESGO
abrir ↗Referência
CVE-2026-13170
Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
41RIESGO
abrir ↗Referência
CVE-2026-12971
LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
28RIESGO
abrir ↗Referência
CVE-2026-17018
CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
33RIESGO
abrir ↗Referência
CVE-2026-17010
Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
33RIESGO
abrir ↗Referência
CVE-2026-17016
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
28RIESGO
abrir ↗Referência
CVE-2026-17012
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
33RIESGO
abrir ↗Referência
CVE-2026-18666
Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
33RIESGO
abrir ↗Referência
CVE-2019-2000
In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local
23RIESGO
abrir ↗Referência
CVE-2026-9478
Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection
48RIESGO
abrir ↗Referência
D-Link DWL-2600AP - Multiple OS Command Injection
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Config
60RIESGO
abrir ↗Referência
CVE-2026-19375
dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-19353
DedeCMS Installation Wizard index.php _4_Setup file inclusion
28RIESGO
abrir ↗Referência
CVE-2026-9428
Tenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir ↗Referência
CVE-2018-25350
userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.