Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
Referência
CVE-2026-14842
Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass
33RIESGO
abrir
Referência
CVE-2026-14812
Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
48RIESGO
abrir
Referência
CVE-2020-17519
CVE-2020-17519CRITICALbajo ataque
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
Referência
CVE-2026-66748
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RIESGO
abrir
Referência
CVE-2026-43760
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe
41RIESGO
abrir
Referência
CVE-2025-15662
Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery
41RIESGO
abrir
Referência
CVE-2026-13399
Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order
41RIESGO
abrir
Referência
CVE-2026-14306
Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass
33RIESGO
abrir
Referência
CVE-2026-12584
Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback
41RIESGO
abrir
Referência
CVE-2026-11361
Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status
33RIESGO
abrir
Referência
CVE-2026-39931
OpenEMR Authenticated SQL Injection via backup.php Import Feature
41RIESGO
abrir
Referência
CVE-2026-41453
Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter
41RIESGO
abrir
Referência
CVE-2026-18604
textPlus Text Message and Call App com.gogii.textplus DialerActivity improper export of android application components
33RIESGO
abrir
Referência
CVE-2026-15193
AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
33RIESGO
abrir
Referência
CVE-2026-15184
GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
33RIESGO
abrir
Referência
CVE-2026-14798
CodeAstro Apartment Visitor Management System visitor-entry.php sql injection
33RIESGO
abrir
Referência
CVE-2026-66746
Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
33RIESGO
abrir
Referência
CVE-2018-25351
Joomla! Component EkRishta 2.10 SQL Injection via username
41RIESGO
abrir
Referência
CVE-2026-9299
omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption
33RIESGO
abrir
Referência
CVE-2026-9298
omec-project amf PathSwitchRequest memory corruption
33RIESGO
abrir
Referência
CVE-2026-13597
QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover
48RIESGO
abrir
Referência
CVE-2020-20139
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table
23RIESGO
abrir
Referência
CVE-2020-20141
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Tab
23RIESGO
abrir
Referência
CVE-2026-63720
datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field
41RIESGO
abrir
Referência
CVE-2023-47268
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RIESGO
abrir
Referência
CVE-2024-46508
yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting
41RIESGO
abrir
Referência
CVE-2026-64822
djangoSIGE 1.10 User Enumeration via ForgotPasswordView
33RIESGO
abrir
Referência
CVE-2026-13694
Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass
33RIESGO
abrir
Referência
CVE-2026-13693
Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal
33RIESGO
abrir
Referência
CVE-2020-20277
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver
28RIESGO
abrir
anteriorpágina 517 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.