Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2026-61511
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
48RIESGO
abrir
Referência
CVE-2012-2584
Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitr
23RIESGO
abrir
Referência
CVE-2026-14189
WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields
28RIESGO
abrir
Referência
CVE-2012-2591
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attack
23RIESGO
abrir
Referência
CVE-2025-71408
NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments
41RIESGO
abrir
Referência
CVE-2026-65709
sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API
41RIESGO
abrir
Referência
CVE-2012-2601
SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2023-3519
CVE-2023-3519CRITICALbajo ataqueransomware
Unauthenticated remote code execution
100RIESGO
abrir
Referência
CVE-2010-1472
Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attac
43RIESGO
abrir
Referência
CVE-2026-8189
Wavlink NU516U1 adm.cgi wzdrepeater os command injection
33RIESGO
abrir
Referência
CVE-2026-8188
Wavlink NU516U1 adm.cgi change_wifi_password os command injection
33RIESGO
abrir
Referência
CVE-2025-5640
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RIESGO
abrir
Referência
CVE-2010-0690
SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2012-2740
SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2026-63100
Maybe 0.6.0 Missing Authorization via HostingsController show/update
41RIESGO
abrir
Referência
CVE-2026-63099
TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints
41RIESGO
abrir
Referência
CVE-2026-63096
Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
33RIESGO
abrir
Referência
CVE-2026-63095
Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint
41RIESGO
abrir
Referência
CVE-2026-63093
Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
41RIESGO
abrir
Referência
CVE-2026-63094
SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft
41RIESGO
abrir
Referência
CVE-2026-16017
mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
33RIESGO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir
Referência
CVE-2026-16014
code-projects Hospital Bed Management System Login Form sql injection
33RIESGO
abrir
Referência
CVE-2026-16013
liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
33RIESGO
abrir
Referência
CVE-2026-11966
User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler
33RIESGO
abrir
Referência
CVE-2026-11961
User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
41RIESGO
abrir
Referência
CVE-2026-11575
PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback
41RIESGO
abrir
anteriorpágina 618 / 753siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.