Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8811Nuclei 4349Metasploit 3488✓ solo verificadosrecientespopularesriesgo
22.657 exploits
Referência
CVE-2010-4502
Integer overflow in KmxSbx.sys 6.2.0.22 in CA Internet Security Suite Plus 2010 allows local users to cause a denial of
23RIESGO
abrir ↗Referência
CVE-2010-4566
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and
43RIESGO
abrir ↗Referência
CVE-2010-4598
Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary f
28RIESGO
abrir ↗Referência
CVE-2026-7750
Totolink N300RH POST Request cstecgi.cgi setMacFilterRules buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-7749
Totolink N300RH POST Request cstecgi.cgi setWanConfig buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-7748
Totolink N300RH POST Request cstecgi.cgi setUpgradeFW buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-7747
Totolink N300RH Parameter cstecgi.cgi loginauth buffer overflow
48RIESGO
abrir ↗Referência
CVE-2014-10038
SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência
CVE-2010-4609
SQL injection vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência
CVE-2026-12586
Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset
41RIESGO
abrir ↗Referência
CVE-2026-11872
Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via save_clever_menu_item
33RIESGO
abrir ↗Referência
CVE-2026-14920
AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter
41RIESGO
abrir ↗Referência
CVE-2026-58658
GPUStack Unauthenticated Information Disclosure via Worker Endpoints
41RIESGO
abrir ↗Referência
CVE-2026-11580
Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
33RIESGO
abrir ↗Referência
CVE-2014-1202
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a c
23RIESGO
abrir ↗Referência
CVE-2014-1459
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RIESGO
abrir ↗Referência
CVE-2026-7213
ef10007 MLOps_MCP save_file Tool fastmcp_server.py path traversal
33RIESGO
abrir ↗Referência
CVE-2026-7211
dvladimirov MCP Git Search API mcp_server.py GitSearchRequest command injection
33RIESGO
abrir ↗Referência
CVE-2026-7205
duartium papers-mcp-server main.py search_papers path traversal
33RIESGO
abrir ↗Referência
CVE-2026-7204
Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7203
Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection
48RIESGO
abrir ↗Referência
CVE-2026-38651
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw
41RIESGO
abrir ↗Referência
CVE-2026-7202
Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7146
AlejandroArciniegas mcp-data-vis HTTP Request server.js axios server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-7143
1000 Projects Portfolio Management System MCA block_status.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7142
Wooey API Endpoint scripts.py add_or_update_script improper authorization
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.