Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2026-14647
onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
33RIESGO
abrir
Referência
CVE-2026-58453
JAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc
48RIESGO
abrir
Referência
CVE-2026-13567
code-projects Online Music Site POST Request Feedback.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-40524
FrontAccounting < 2.4.20 SQL Injection via get_gl_transactions()
41RIESGO
abrir
Referência
CVE-2026-13561
Edimax EW-7478APC POST Request formiNICbasic os command injection
33RIESGO
abrir
ReferênciaVexDay Proof
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
CVE-2019-11537webappsphp
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RIESGO
abrir
Referência
CVE-2019-1153
Microsoft Graphics Component Information Disclosure Vulnerability
33RIESGO
abrir
Referência
CVE-2019-11539
CVE-2019-11539HIGHbajo ataqueransomware
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
Referência
CVE-2026-13549
CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization
33RIESGO
abrir
Referência
CVE-2026-5484
BookStackApp BookStack Chapter Export ExportFormatter.php chapterToMarkdown access control
33RIESGO
abrir
Referência
CVE-2026-5323
priyankark a11y-mcp index.js A11yServer server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-1540
Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution
41RIESGO
abrir
Referência
CVE-2026-5322
AlejandroArciniegas mcp-data-vis MCP server.js request sql injection
33RIESGO
abrir
Referência
CVE-2026-5321
vanna-ai vanna FastAPI/Flask Server cross-domain policy
33RIESGO
abrir
Referência
CVE-2026-5320
vanna-ai vanna Chat API Endpoint v2 missing authentication
33RIESGO
abrir
Referência
CVE-2026-5319
itsourcecode Payroll Management System navbar.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5318
LibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds write
33RIESGO
abrir
Referência
CVE-2026-5317
Nothings stb stb_vorbis.c start_decoder out-of-bounds write
33RIESGO
abrir
Referência
CVE-2026-1879
Harvard University IQSS Dataverse Theme Customization ThemeAndWidgets.xhtml unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-5261
Shandong Hoteam InforCenter PLM BaseHandler.ashx uploadFileToIIS unrestricted upload
33RIESGO
abrir
Referência
CVE-2025-15484
Order Notification for WooCommerce < 3.6.3 - Unauthenticated WooCommerce REST Permission Bypass
48RIESGO
abrir
Referência
CVE-2026-5255
code-projects Simple Laundry System Parameter delstaffinfo.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5254
welovemedia FFmate Webhook AppJsonTreeView.vue cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5253
bufanyun HotGo editNotice Endpoint MessageList.vue cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5252
z-9527 admin Message Create Endpoint message.js cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5251
z-9527 admin User Update Endpoint user.js dynamically-determined object attributes
33RIESGO
abrir
Referência
CVE-2026-5249
gougucms Record Endpoint record.html cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5248
gougucms User Registration Login.php reg_submit dynamically-determined object attributes
33RIESGO
abrir
Referência
CVE-2026-35057
XenForo Stored Cross-Site Scripting via Structured Text Mentions
33RIESGO
abrir
Referência
CVE-2026-79845
code-projects Simple Inventory System edit.php sql injection
33RIESGO
abrir
anteriorpágina 704 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.