Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8663Nuclei 4287Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.332 exploits
Referência
CVE-2026-11466
zilliztech deep-searcher collection_router.py CollectionRouter.invoke access control
33RIESGO
abrir ↗Referência
CVE-2026-11462
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-11461
NousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization
33RIESGO
abrir ↗Referência
CVE-2026-11460
Boost Serialization improper validation of specified type of input
33RIESGO
abrir ↗Referência
CVE-2026-49494
Xcitium Client Security / Comodo Internet Security Remote Denial of Service
41RIESGO
abrir ↗Referência
CVE-2026-11456
Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11453
Tiobon Employee Self-Service System Login Endpoint BlogSearch.aspx sql injection
33RIESGO
abrir ↗Referência
CVE-2020-0674
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir ↗Referência
File Sharing Wizard 1.5.0 - POST SEH Overflow
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RIESGO
abrir ↗Referência
CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir ↗Referência
CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir ↗Referência
CVE-2026-15495
SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection
33RIESGO
abrir ↗Referência
CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir ↗Referência
CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir ↗Referência
CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir ↗Referência
CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir ↗Referência
CVE-2026-16258
Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint
48RIESGO
abrir ↗Referência
CVE-2026-16041
MStore API < 4.21.0 - Unauthenticated Product Review Creation
41RIESGO
abrir ↗Referência
CVE-2026-16039
MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR
33RIESGO
abrir ↗Referência
CVE-2026-16038
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
48RIESGO
abrir ↗Referência
CVE-2026-16030
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
41RIESGO
abrir ↗Referência
CVE-2026-19193 Proof of Concept
Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control
41RIESGO
abrir ↗Referência
CVE-2026-19192
DeepCool DisplayService DeepCoolDisplayService.exe access control
41RIESGO
abrir ↗Referência
CVE-2026-19191
StableBit DrivePool DrivePoolService DrivePool.Service.exe permission
41RIESGO
abrir ↗Referência
CVE-2026-19190
StableBit Scanner ScannerService Scanner.Service.exe permission
41RIESGO
abrir ↗Referência
CVE-2026-19189
Power Sofware PowerISO Kernel Driver scdemu.sys privileges management
41RIESGO
abrir ↗Referência
CVE-2026-15147
Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR
33RIESGO
abrir ↗Referência
CVE-2026-10524
CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation
41RIESGO
abrir ↗Referência
CVE-2026-14936
Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.