Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.295exploits catalogados
36.048CVEs con explotación pública
24.695probados en laboratorio
22.657 exploits
Referência
CVE-2026-4512
WP reCaptcha by WebDesignBy < 2.0 – Admin+ Stored XSS
28RIESGO
abrir
Referência
CVE-2026-4106
HT Mega < 3.0.7 – Unauthenticated PII Disclosure
48RIESGO
abrir
Referência
CVE-2026-6878
ByteDance verl grader.py math_equal sandbox
33RIESGO
abrir
Referência
CVE-2026-6874
ericc-ch copilot-api Header token dns rebinding
33RIESGO
abrir
Referência
CVE-2026-40517
radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names
41RIESGO
abrir
Referência
CVE-2026-34413
Xerte Online Toolkits Missing Authentication via connector.php
56RIESGO
abrir
Referência
CVE-2026-34415
Xerte Online Toolkits File Upload RCE via elfinder Connector
63RIESGO
abrir
ReferênciaVexDay Proof
Absolute Control Panel XE 1.5 - Insecure Cookie Handling
CVE-2008-6859webappsphp
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative ac
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Live Support 5.1 - Insecure Cookie Handling
CVE-2008-6864webappsphp
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative a
23RIESGO
abrir
ReferênciaVexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6870webappsasp
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information
23RIESGO
abrir
ReferênciaVexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6871webappsasp
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers t
23RIESGO
abrir
Referência
CVE-2014-0997
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RIESGO
abrir
Referência
CVE-2014-0997
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RIESGO
abrir
Referência
CVE-2014-0999
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive
23RIESGO
abrir
ReferênciaVexDay Proof
dotProject 2.0.4 - 'baseDir' Remote File Inclusion
CVE-2006-4234webappsphp
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
CVE-2008-6917webappsphp
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2026-63098
TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
33RIESGO
abrir
ReferênciaVexDay Proof
ThePortal 2.2 - Arbitrary File Upload
CVE-2008-6918webappsphp
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RIESGO
abrir
Referência
CVE-2026-63094
SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft
41RIESGO
abrir
ReferênciaVexDay Proof
TaskDriver 1.3 - Remote Change Admin Password
CVE-2008-6919webappsphp
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative acce
23RIESGO
abrir
Referência
CVE-2026-16017
mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
33RIESGO
abrir
ReferênciaVexDay Proof
PHPAdBoard - PHP uploads Arbitrary File Upload
CVE-2008-6921webappsphp
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code
23RIESGO
abrir
Referência
CVE-2017-8926
Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspeci
23RIESGO
abrir
Referência
CVE-2026-6621
1024bit extend-deep index.js prototype pollution
33RIESGO
abrir
Referência
CVE-2014-10014
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attacke
23RIESGO
abrir
Referência
CVE-2014-10020
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir
anteriorpágina 697 / 756siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.