Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.510exploits catalogados
35.602CVEs con explotación pública
24.695probados en laboratorio
22.332 exploits
Referência
CVE-2026-10271
a4m4 Student-Management-System Admin Endpoint admin redirect
33RIESGO
abrir
Referência
CVE-2026-10209
code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection
33RIESGO
abrir
Referência
CVE-2026-10208
code-projects Online Hospital Management System login_1.php login_user sql injection
33RIESGO
abrir
Referência
CVE-2026-10206
D-Link DI-8400 dbsrv.asp stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-10183
TRENDnet TEW-432BRP formWlanSetup stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-10166
Edimax BR-6478AC POST Request formWlbasic command injection
33RIESGO
abrir
Referência
CVE-2026-10161
TRENDnet TEW-432BRP formResetStatistic stack-based overflow
41RIESGO
abrir
Referência
CVE-2019-7440
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RIESGO
abrir
Referência
CVE-2019-7442
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault
35RIESGO
abrir
Referência
CVE-2019-8196
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
Referência
CVE-2019-8452
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security clien
23RIESGO
abrir
Referência
CVE-2019-8926
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zon
23RIESGO
abrir
Referência
CVE-2026-9460
Edimax EW-7438RPn formAccept stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9459
Edimax EW-7438RPn formConnectionSetting stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9458
Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-9457
Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection
48RIESGO
abrir
Referência
CVE-2026-9451
code-projects Employee Management System applyleaveprocess.php sql injection
33RIESGO
abrir
Referência
CVE-2020-37232
Advanced System Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2020-37231
Privacy Drive 3.17.0 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
Bolt CMS 3.6.4 - Cross-Site Scripting
CVE-2019-9553webappsphp
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and
23RIESGO
abrir
Referência
CVE-2026-9432
Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-9430
Tenda F1202 GstDhcpSetSerof formGstDhcpSetSer stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9429
Tenda F1202 WrlExtraSet formWrlExtraSet stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9427
Edimax EW-7438RPn webs formWlSiteSurvey stack-based overflow
41RIESGO
abrir
Referência
Craft CMS 3.1.12 Pro - Cross-Site Scripting
CVE-2019-9554webappsphp
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at
23RIESGO
abrir
Referência
CVE-2019-9581
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RIESGO
abrir
Referência
CVE-2026-9426
Edimax EW-7438RPn formHwSet stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9416
code-projects Employee Management System myprofile.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-9415
code-projects Employee Management System eloginwel.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-9413
SourceCodester Indian Invoicing System category.php cross site scripting
33RIESGO
abrir
anteriorpágina 484 / 745siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.