Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência✓ VexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RIESGO
abrir ↗Referência
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir ↗Referência
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir ↗Referência
CVE-2026-16959
Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
33RIESGO
abrir ↗Referência
CVE-2026-16576
Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API
41RIESGO
abrir ↗Referência
CVE-2026-16575
Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint
33RIESGO
abrir ↗Referência
CVE-2026-13736
NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
33RIESGO
abrir ↗Referência
CVE-2026-77392
SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.php saveUser sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14287
TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass
33RIESGO
abrir ↗Referência
CVE-2026-14196
WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR
33RIESGO
abrir ↗Referência
CVE-2026-13175
Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
33RIESGO
abrir ↗Referência
CVE-2026-12983
Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection
41RIESGO
abrir ↗Referência
CVE-2026-11565
Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui
41RIESGO
abrir ↗Referência
CVE-2026-76048
SourceCodester Simple Online Food Ordering System ajax.php login sql injection
33RIESGO
abrir ↗Referência
CVE-2026-17533
All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
41RIESGO
abrir ↗Referência
CVE-2026-16949
Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup
33RIESGO
abrir ↗Referência
CVE-2026-14941
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
33RIESGO
abrir ↗Referência
CVE-2026-17012
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
33RIESGO
abrir ↗Referência
CVE-2026-18666
Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
33RIESGO
abrir ↗Referência
CVE-2026-18032
WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass
41RIESGO
abrir ↗Referência
CVE-2026-16038
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
48RIESGO
abrir ↗Referência
CVE-2026-16030
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
41RIESGO
abrir ↗Referência
CVE-2026-10599
Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.