Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2026-11479
yoanbernabeu grepai Qdrant Backend chunker.go weak hash
28RIESGO
abrir
Referência
CVE-2026-11478
kokke tiny-regex-c Pattern re.c matchstar redos
33RIESGO
abrir
Referência
CVE-2023-54351
WordPress Sonaar Music Plugin 4.7 Stored XSS via Comments
33RIESGO
abrir
Referência
CVE-2023-54350
WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated
41RIESGO
abrir
Referência
CVE-2022-50953
WordPress Plugin admin-word-count-column 2.2 Local File Read
33RIESGO
abrir
Referência
CVE-2019-7256
CVE-2019-7256CRITICALbajo ataque
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir
Referência
CVE-2019-7276
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RIESGO
abrir
Referência
snapd < 2.37 (Ubuntu) - 'dirty_sock' Local Privilege Escalation (1)
CVE-2019-7304HIGHlocallinux
Local privilege escalation via snapd socket
53RIESGO
abrir
Referência
CVE-2026-10272
a4m4 Student-Management-System deleteform.php improper authorization
33RIESGO
abrir
Referência
CVE-2026-10271
a4m4 Student-Management-System Admin Endpoint admin redirect
33RIESGO
abrir
Referência
CVE-2026-10209
code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection
33RIESGO
abrir
Referência
CVE-2026-10208
code-projects Online Hospital Management System login_1.php login_user sql injection
33RIESGO
abrir
Referência
CVE-2026-10206
D-Link DI-8400 dbsrv.asp stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-10183
TRENDnet TEW-432BRP formWlanSetup stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-10166
Edimax BR-6478AC POST Request formWlbasic command injection
33RIESGO
abrir
Referência
CVE-2026-10161
TRENDnet TEW-432BRP formResetStatistic stack-based overflow
41RIESGO
abrir
Referência
CVE-2019-7440
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RIESGO
abrir
Referência
CVE-2019-7442
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault
35RIESGO
abrir
Referência
CVE-2019-8196
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
Referência
CVE-2019-8452
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security clien
23RIESGO
abrir
Referência
CVE-2019-8926
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zon
23RIESGO
abrir
Referência
CVE-2026-9460
Edimax EW-7438RPn formAccept stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9459
Edimax EW-7438RPn formConnectionSetting stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-9458
Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-9457
Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection
48RIESGO
abrir
Referência
CVE-2026-9451
code-projects Employee Management System applyleaveprocess.php sql injection
33RIESGO
abrir
Referência
CVE-2021-4034
CVE-2021-4034HIGHbajo ataqueransomware
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Referência
CVE-2021-4034
CVE-2021-4034HIGHbajo ataqueransomware
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Referência40
crixpwn/CVE-2026-8389
JIT miscompilation in the JavaScript Engine: JIT component
41RIESGO
abrir
Referência
CVE-2022-50965
uBidAuction 2.0.1 posts manage Reflected XSS
33RIESGO
abrir
anteriorpágina 492 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.