Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
22.697 exploits
Referência
CVE-2026-5987
Sanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engine
33RIESGO
abrir
Referência
CVE-2026-5986
Zod jsVideoUrlParser util.js getTime redos
33RIESGO
abrir
Referência
CVE-2026-5985
code-projects Simple IT Discussion Forum crud.php sql injection
33RIESGO
abrir
Referência
CVE-2018-18419
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filen
23RIESGO
abrir
Referência
CVE-2026-5044
Belkin F9K1122 Setting formSetSystemSettings stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5043
Belkin F9K1122 Parameter formSetPassword stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5042
Belkin F9K1122 Parameter formCrossBandSwitch stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5041
code-projects Chamber of Commerce Membership Management System pageMail.php fwrite command injection
33RIESGO
abrir
Referência
CVE-2026-5037
mxml mxmlIndexNew mxml-index.c index_sort stack-based overflow
33RIESGO
abrir
Referência
CVE-2026-5036
Tenda 4G06 Endpoint DhcpListClient fromDhcpListClient stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5035
code-projects Accounting System Parameter view_work.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5034
code-projects Accounting System Parameter edit_costumer.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5033
code-projects Accounting System Parameter view_costumer.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5031
BichitroGan ISP Billing Software Endpoint users-view resource injection
33RIESGO
abrir
Referência
CVE-2026-5030
Totolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection
33RIESGO
abrir
Referência
CVE-2026-5024
D-Link DIR-513 formSetEmail stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5023
DeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injection
33RIESGO
abrir
Referência
CVE-2026-5021
Tenda F453 httpd PPTPUserSetting fromPPTPUserSetting stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5020
Totolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection
33RIESGO
abrir
Referência
CVE-2026-5019
code-projects Simple Food Order System Parameter all-orders.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5018
code-projects Simple Food Order System Parameter register-router.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5017
code-projects Simple Food Order System Parameter all-tickets.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5016
elecV2 elecV2P URL mock eAxios server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-5015
elecV2 elecV2P Endpoint logs cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5014
elecV2 elecV2P Wildcard log path.join path traversal
33RIESGO
abrir
Referência
CVE-2026-5013
elecV2 elecV2P :key path.join path traversal
33RIESGO
abrir
Referência
CVE-2026-5012
elecV2 elecV2P rpc pm2run os command injection
33RIESGO
abrir
Referência
CVE-2026-5011
elecV2 elecV2P JSON webhook runJSFile code injection
33RIESGO
abrir
Referência
CVE-2026-5007
kazuph mcp-docs-rag add_git_repository/add_text_file index.ts cloneRepository os command injection
33RIESGO
abrir
Referência
CVE-2026-5004
Wavlink WL-WN579X3-C UPNP firewall.cgi sub_4019FC stack-based overflow
41RIESGO
abrir
anteriorpágina 700 / 757siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.