Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
22.657 exploits
Referência
CVE-2026-5418
appsmithorg appsmith Dashboard WebClientUtils.java computeDisallowedHosts server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-5559
AntaresMugisho PyBlade AST Validation sandbox.py _is_safe_ast special elements used in a template engine
33RIESGO
abrir
Referência
CVE-2026-5558
PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection
33RIESGO
abrir
Referência
CVE-2018-25251
Snes9K 0.0.9z Buffer Overflow SEH via Netplay Socket
41RIESGO
abrir
Referência
CVE-2018-25250
MyBB Last User's Threads in Profile Plugin 1.2 Persistent XSS
33RIESGO
abrir
Referência
CVE-2018-25249
MyBB My Arcade Plugin 1.3 Persistent XSS via Comment
33RIESGO
abrir
Referência
CVE-2018-25248
MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php
33RIESGO
abrir
Referência
CVE-2018-25247
MyBB Like Plugin 3.0.0 Cross-Site Scripting via User Profiles
33RIESGO
abrir
Referência
CVE-2018-25245
7 Tik 1.0.1.0 Denial of Service via Search
41RIESGO
abrir
Referência
CVE-2018-25244
Eco Search 1.0.2.0 Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25243
FastTube 1.0.1.0 Denial of Service via Search
33RIESGO
abrir
Referência
CVE-2018-25242
One Search 1.1.0.0 Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25241
VPN Browser+ 1.1.0.0 Denial of Service
41RIESGO
abrir
Referência
CVE-2026-75082
Webkul Bagisto Customer-Registration Notification Email register cross site scripting
33RIESGO
abrir
Referência
CVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
Referência
CVE-2026-19963
Edimax EW-7478APC stainfo command injection
33RIESGO
abrir
Referência
CVE-2026-19962
Edimax EW-7478APC setWAN command injection
33RIESGO
abrir
Referência
CVE-2026-19957
graphlit graphlit-mcp-server ssrf-test Endpoint tools.ts fetch server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-5198
code-projects Student Membership System Admin Login index.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5197
code-projects Student Membership System delete_user.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5196
code-projects Student Membership System delete_member.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5184
TRENDnet TEW-713RE setSysAdm command injection
33RIESGO
abrir
Referência
CVE-2026-3881
Performance Monitor <= 1.0.6 - Unauthenticated Blind SSRF
33RIESGO
abrir
Referência
CVE-2026-5183
TRENDnet TEW-713RE addRouting sub_421494 command injection
33RIESGO
abrir
Referência
CVE-2026-16594
WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
41RIESGO
abrir
Referência
CVE-2026-19190
StableBit Scanner ScannerService Scanner.Service.exe permission
41RIESGO
abrir
Referência
CVE-2018-10576
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentica
23RIESGO
abrir
Referência
CVE-2026-11962
FileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File Operations
41RIESGO
abrir
Referência
CVE-2026-70616
boringproxy 0.10.0 Resource Exhaustion DoS via GET /loading endpoint
41RIESGO
abrir
Referência
CVE-2026-14771
SourceCodester Class and Exam Timetabling System edit_exam1.php sql injection
33RIESGO
abrir
anteriorpágina 680 / 756siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.