Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência
CVE-2019-25726
All in One Video Downloader 1.2 SQL Injection via admin page-edit
41RIESGO
abrir ↗Referência
CVE-2026-15471
Eleveo Call Recording Software pci_dss_status.jsp improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-15470
Eleveo Call Recording Software group.jsp improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-15311
NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-10810
itsourcecode Fees Management System navbar.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-7716
code-projects Gym Management System In PHP/Windows NT index.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7071
CodeAstro Online Job Portal user-cvs file information disclosure
33RIESGO
abrir ↗Referência
CVE-2026-7069
D-Link DIR-825 miniupnpd upnpsoap.c AddPortMapping buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-47123
FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path
41RIESGO
abrir ↗Referência
CVE-2026-75012
TOTOLINK EX1200L Password Configuration cstecgi.cgi setPasswordCfg null pointer dereference
41RIESGO
abrir ↗Referência
CVE-2026-19997
Webkul Bagisto Backend Sales RMA Endpoint requests authorization
33RIESGO
abrir ↗Referência
CVE-2011-4340
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow
23RIESGO
abrir ↗Referência
CVE-2026-19996
Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges management
33RIESGO
abrir ↗Referência✓ VexDay Proof
Minichat 6.0 - 'ftag.php' Remote File Inclusion
PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗Referência✓ VexDay Proof
Limbo CMS - Private Messaging Component SQL Injection
SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote att
23RIESGO
abrir ↗Referência
CVE-2026-15696
Tenda BE12 Pro VirtualSer fromVirtualSer stack-based overflow
41RIESGO
abrir ↗Referência
Security research on Craft CMS authentication mechanism
Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate
41RIESGO
abrir ↗Referência
CVE-2021-47935
Sentry 8.2.0 Remote Code Execution via Pickle Deserialization
41RIESGO
abrir ↗Referência
CVE-2026-7718
Totolink WA300 POST Request cstecgi.cgi setWebWlanIdx command injection
33RIESGO
abrir ↗Referência
CVE-2026-7717
Totolink WA300 POST Request cstecgi.cgi UploadCustomModule buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-7024
rawchen sims deleteFileServlet Endpoint DeleteFileServlet.java path traversal
33RIESGO
abrir ↗Referência
CVE-2026-6602
rickxy Hospital Management System his_admin_account.php unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2017-11911
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.