Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.332 exploits
Referência
CVE-2018-25337
Joomla JoomOCShop 1.0 Cross-Site Request Forgery
33RIESGO
abrir
Referência
CVE-2026-15317
Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-15182
GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-11869
WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subject Access Request
33RIESGO
abrir
Referência
CVE-2026-23697
Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
41RIESGO
abrir
Referência
CVE-2026-7823
Totolink A8000RU cstecgi.cgi setAppFilterCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-7822
itsourcecode Courier Management System print_pdets.php sql injection
33RIESGO
abrir
Referência
CVE-2026-7812
54yyyu code-mcp MCP Tool server.py git_operation command injection
33RIESGO
abrir
Referência
CVE-2026-7811
54yyyu code-mcp MCP File server.py is_safe_path path traversal
33RIESGO
abrir
Referência
CVE-2026-7741
CodeAstro Online Classroom studentlogin sql injection
33RIESGO
abrir
Referência
CVE-2026-7725
PrefectHQ prefect GitRepository Pull storage.py argument injection
33RIESGO
abrir
Referência
CVE-2026-7724
PrefectHQ prefect Webhook/Notification validate_restricted_url toctou
28RIESGO
abrir
Referência
CVE-2020-6519
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy
28RIESGO
abrir
Referência
CVE-2019-2729
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RIESGO
abrir
Referência
CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
Referência
CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
Referência
CVE-2026-34115
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe_amazon.php
48RIESGO
abrir
Referência
CVE-2026-11794
Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
41RIESGO
abrir
Referência
CVE-2026-11562
WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
33RIESGO
abrir
Referência
CVE-2026-13582
Edimax EW-7478APC POST Request formUSBAccount buffer overflow
41RIESGO
abrir
Referência
CVE-2026-13581
Edimax EW-7478APC POST Request formStaDrvSetup os command injection
33RIESGO
abrir
Referência
CVE-2026-40522
FrontAccounting < 2.4.20 SQL Injection via rep601.php
41RIESGO
abrir
Referência
CVE-2026-13509
RAGapp Knowledge File files.py FileHandler.remove_file path traversal
33RIESGO
abrir
Referência
CVE-2026-13508
khoj-ai khoj Conversation Sharing api_chat.py authorization
33RIESGO
abrir
Referência
CVE-2026-13504
code-projects Project Management System Mail Compose mail.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-13503
antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
33RIESGO
abrir
Referência
CVE-2026-13502
antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou
28RIESGO
abrir
Referência
CVE-2026-13501
antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
33RIESGO
abrir
Referência
CVE-2022-50971
Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2021-47985
Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
anteriorpágina 487 / 745siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.