Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8663Nuclei 4287Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.332 exploits
Referência
CVE-2026-8071
Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass
41RIESGO
abrir ↗Referência
CVE-2026-4986
WPForms Lite < 1.10.0.5 – Unauthenticated PayPal Webhook Forgery
33RIESGO
abrir ↗Referência
CVE-2026-11618
DTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle improper authentication
33RIESGO
abrir ↗Referência
CVE-2026-11556
Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection
41RIESGO
abrir ↗Referência
CVE-2026-11521
Mohammed-eid35 bank-management-system-springboot Transaction Endpoint TransactionController.java improper authorization
33RIESGO
abrir ↗Referência✓ VexDay Proof
JiRos FAQ Manager 1.0 - 'index.asp' SQL Injection
SQL injection vulnerability in index.asp in JiRos FAQ Manager 1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência
CVE-2017-14712
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
23RIESGO
abrir ↗Referência
CVE-2017-14717
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
23RIESGO
abrir ↗Referência
WinWaste.NET 1.0.6183.16475 - Privilege Escalation due Incorrect Access Control
WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executa
23RIESGO
abrir ↗Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection
SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2006-6184
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RIESGO
abrir ↗Referência
CVE-2006-6184
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RIESGO
abrir ↗Referência
CVE-2026-10694
SourceCodester Online Food Ordering System index.php include file inclusion
33RIESGO
abrir ↗Referência
CVE-2013-1763
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RIESGO
abrir ↗Referência
CVE-2026-10299
code-projects Online Hospital Management System viewdoctortimings.php resource injection
33RIESGO
abrir ↗Referência
CVE-2026-10277
j3k0 mcp-google-workspace MCP Gmail Tool gmail.ts saveToDisk access control
33RIESGO
abrir ↗Referência
CVE-2026-10274
indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMetadata server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-10226
raisulislamg4 student_management_system_by_php delete.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-10225
raisulislamg4 student_management_system_by_php Login login_check.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-10222
NousResearch hermes-agent config.py _sanitize_env_lines injection
33RIESGO
abrir ↗Referência
CVE-2026-10221
NousResearch hermes-agent run_agent.py _compress_context injection
33RIESGO
abrir ↗Referência
CVE-2018-25422
MOGG web simulator Script All Version SQL Injection via play.php
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.