Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8663Nuclei 4287Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.367 exploits
Referência
CVE-2026-8218
Devs Palace ERP Online purchase_return_save cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-8217
Industrial Application Software IAS Canias ERP RMI Runtime.getRuntime.exec os command injection
33RIESGO
abrir ↗Referência
CVE-2026-8217
Industrial Application Software IAS Canias ERP RMI Runtime.getRuntime.exec os command injection
33RIESGO
abrir ↗Referência
CVE-2026-19343
code-projects Task Management System AdminLogin.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-19342
code-projects Task Management System Login index.php improper authentication
33RIESGO
abrir ↗Referência
CVE-2026-19341
UTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2020-14882
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗Referência
CVE-2023-47268
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RIESGO
abrir ↗Referência
CVE-2024-46508
yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting
41RIESGO
abrir ↗Referência
CVE-2026-13694
Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass
33RIESGO
abrir ↗Referência
CVE-2026-13693
Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal
33RIESGO
abrir ↗Referência
CVE-2020-20277
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver
28RIESGO
abrir ↗Referência
CVE-2020-2038
PAN-OS: OS command injection vulnerability in the management web interface
78RIESGO
abrir ↗Referência
CVE-2020-2096
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref
60RIESGO
abrir ↗Referência
b2evolution 6.11.6 - 'plugin name' Stored XSS
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution
23RIESGO
abrir ↗Referência
CVE-2020-23522
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
23RIESGO
abrir ↗Referência
Tailor MS 1.0 - Reflected Cross-Site Scripting
A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Mana
33RIESGO
abrir ↗Referência
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa
28RIESGO
abrir ↗Referência✓ VexDay Proof
RiteCMS 2.2.1 - Authenticated Remote Code Execution
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php
28RIESGO
abrir ↗Referência
CVE-2020-23972
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating
50RIESGO
abrir ↗Referência
CVE-2026-16032
LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring
33RIESGO
abrir ↗Referência
CVE-2026-15239
Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key
33RIESGO
abrir ↗Referência
CVE-2026-15211
Subscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Capture Token
33RIESGO
abrir ↗Referência
CVE-2026-11767
CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form
41RIESGO
abrir ↗Referência
CVE-2026-63767
ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ
48RIESGO
abrir ↗Referência
CVE-2026-63768
cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State
33RIESGO
abrir ↗Referência
CVE-2020-35391
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RIESGO
abrir ↗Referência
PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting)
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admi
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.