Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência
CVE-2024-33288
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the
56RIESGO
abrir ↗Referência
CVE-2026-7810
UsamaK98 python-notebook-mcp server.py add_cell path traversal
33RIESGO
abrir ↗Referência
CVE-2026-41471
Easy PayPal Events & Tickets < 1.4 Information Disclosure via QR Code Endpoint
41RIESGO
abrir ↗Referência
CVE-2026-14195
Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
28RIESGO
abrir ↗Referência
CVE-2026-14836
Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass
41RIESGO
abrir ↗Referência
CVE-2026-14596
DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection
41RIESGO
abrir ↗Referência
CVE-2013-7091
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RIESGO
abrir ↗Referência
CVE-2026-14834
Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX
33RIESGO
abrir ↗Referência
CVE-2026-14833
Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute
33RIESGO
abrir ↗Referência
CVE-2016-20087
Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege
41RIESGO
abrir ↗Referência
CVE-2019-1003002
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RIESGO
abrir ↗Referência
CVE-2026-63099
TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints
41RIESGO
abrir ↗Referência
CVE-2011-1715
Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other
23RIESGO
abrir ↗Referência
CentOS Web Panel 0.9.8.789 - NameServer Field Persistent Cross-Site Scripting
CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fiel
23RIESGO
abrir ↗Referência✓ VexDay Proof
exV2 < 2.0.4.3 - 'sort' SQL Injection
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users
23RIESGO
abrir ↗Referência
CVE-2026-12988
WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding
33RIESGO
abrir ↗Referência
CVE-2026-12583
Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field
41RIESGO
abrir ↗Referência
CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) - Cross-Site Scripting
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to
23RIESGO
abrir ↗Referência
CVE-2026-6149
code-projects Vehicle Showroom Management System BookVehicleFunction.php sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
BrudaGB 1.1 - '/admin/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RIESGO
abrir ↗Referência
CVE-2026-14652
SourceCodester Simple and Nice Shopping Cart Script Admin Login login.php sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
BrudaNews 1.1 - '/admin/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RIESGO
abrir ↗Referência
CVE-2026-12220
Yealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-6597
langflow-ai langflow Flow Using API core.py has_api_terms credentials storage
33RIESGO
abrir ↗Referência
CVE-2026-6596
langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2026-6595
ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injection
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.