Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.332 exploits
Referência
CVE-2022-4995
Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
48RIESGO
abrir
Referência
CVE-2026-11466
zilliztech deep-searcher collection_router.py CollectionRouter.invoke access control
33RIESGO
abrir
Referência
CVE-2026-11462
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization
33RIESGO
abrir
Referência
CVE-2026-11461
NousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization
33RIESGO
abrir
Referência
CVE-2026-11460
Boost Serialization improper validation of specified type of input
33RIESGO
abrir
Referência
CVE-2026-49494
Xcitium Client Security / Comodo Internet Security Remote Denial of Service
41RIESGO
abrir
Referência
CVE-2026-11456
Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection
33RIESGO
abrir
Referência
CVE-2026-11453
Tiobon Employee Self-Service System Login Endpoint BlogSearch.aspx sql injection
33RIESGO
abrir
Referência
CVE-2020-0674
CVE-2020-0674HIGHbajo ataque
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Referência
File Sharing Wizard 1.5.0 - POST SEH Overflow
CVE-2019-16724remotewindows
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2026-15495
SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection
33RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2026-16258
Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint
48RIESGO
abrir
Referência
CVE-2026-16041
MStore API < 4.21.0 - Unauthenticated Product Review Creation
41RIESGO
abrir
Referência
CVE-2026-16039
MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR
33RIESGO
abrir
Referência
CVE-2026-16038
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
48RIESGO
abrir
Referência
CVE-2026-16030
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
41RIESGO
abrir
Referência
CVE-2026-19193 Proof of Concept
Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control
41RIESGO
abrir
Referência
CVE-2026-19192
DeepCool DisplayService DeepCoolDisplayService.exe access control
41RIESGO
abrir
Referência
CVE-2026-19191
StableBit DrivePool DrivePoolService DrivePool.Service.exe permission
41RIESGO
abrir
Referência
CVE-2026-19190
StableBit Scanner ScannerService Scanner.Service.exe permission
41RIESGO
abrir
Referência
CVE-2026-19189
Power Sofware PowerISO Kernel Driver scdemu.sys privileges management
41RIESGO
abrir
Referência
CVE-2026-15147
Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR
33RIESGO
abrir
Referência
CVE-2026-10524
CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation
41RIESGO
abrir
Referência
CVE-2026-14936
Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification
33RIESGO
abrir
anteriorpágina 486 / 745siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.