Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2026-13692
PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering
33RIESGO
abrir
Referência
CVE-2019-9881
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RIESGO
abrir
Referência
CVE-2019-9978
CVE-2019-9978MEDIUMbajo ataque
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
Referência
CVE-2020-0009
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This
23RIESGO
abrir
Referência
CVE-2018-25342
Smartshop 1 SQL Injection via search.php
41RIESGO
abrir
Referência
CVE-2018-25341
Smartshop 1 SQL Injection via product.php id Parameter
41RIESGO
abrir
Referência
CVE-2020-0646
CVE-2020-0646CRITICALbajo ataque
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RIESGO
abrir
Referência
CVE-2020-0674
CVE-2020-0674HIGHbajo ataque
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Referência
CVE-2020-0688
CVE-2020-0688HIGHbajo ataqueransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Referência
CVE-2020-0688
CVE-2020-0688HIGHbajo ataqueransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2026-14802
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
33RIESGO
abrir
Referência
CVE-2026-14800
imhamzaazam ecommerceFlask cross-site request forgery
33RIESGO
abrir
Referência
CVE-2026-6382
Multiple elFinder Plugins - Authenticated OS Command Injection
48RIESGO
abrir
Referência
CVE-2026-13499
yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-13498
yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection
33RIESGO
abrir
Referência
CVE-2026-13497
itsourcecode Hospital Management System appointment.php sql injection
33RIESGO
abrir
Referência
CVE-2026-13496
itsourcecode Hospital Management System ajaxmedicine.php sql injection
33RIESGO
abrir
Referência
CVE-2026-13495
itsourcecode Hospital Management System adminprofile.php sql injection
33RIESGO
abrir
Referência
CVE-2018-25417
AiOPMSD Final 1.0.0 SQL Injection via quality.php
41RIESGO
abrir
Referência
CVE-2018-25359
Splinterware System Scheduler Pro 5.12 Privilege Escalation
41RIESGO
abrir
Referência
CVE-2026-9464
YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-9462
Edimax EW-7438RPn formWpsProxyEnable stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9425
Edimax EW-7438RPn formWlanMP stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9424
Edimax EW-7438RPn Content-Type formWlanMP os command injection
33RIESGO
abrir
anteriorpágina 489 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.