Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2026-78138
Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html
33RIESGO
abrir
Referência
CVE-2026-13414
CMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajax
33RIESGO
abrir
Referência
CVE-2026-81491
boxpositron with-context-mcp index.ts project_folder path traversal
33RIESGO
abrir
Referência
CVE-2026-80214
LibreNMS Virtualisation Discovery Module RCE
41RIESGO
abrir
Referência
CVE-2026-79912
TOTOLINK N600R cstecgi.cgi getCurrentTime command injection
33RIESGO
abrir
Referência
CVE-2026-79911
TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow
48RIESGO
abrir
Referência
CVE-2026-79804
SililaWijesinghe Food Ordering System search.php sql injection
33RIESGO
abrir
Referência
CVE-2026-80184
In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, appl
41RIESGO
abrir
Referência
CVE-2026-80182
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped au
41RIESGO
abrir
Referência
CVE-2026-79793
code-projects Online Shopping System sumit_form.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-79792
zackees transcribe-anything Yt-dlp Download ytldp_download.py ytdlp_download os command injection
33RIESGO
abrir
Referência
CVE-2026-71510
Dolibarr < 24.0.0 Users REST API SQL Injection via filter parameter
41RIESGO
abrir
Referência
CVE-2026-71509
Dolibarr < 24.0.0 Expense Report REST API Improper Authorization via Update Endpoint
41RIESGO
abrir
Referência
CVE-2026-71508
Dolibarr < 24.0.0 REST API Improper Authorization via User Update Endpoint
41RIESGO
abrir
Referência
CVE-2026-71507
Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Bank Account Routes
41RIESGO
abrir
Referência
CVE-2026-71506
Dolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint
41RIESGO
abrir
Referência1
Original research and non-destructive PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler
Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter
48RIESGO
abrir
Referência
CVE-2026-76070
Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter
48RIESGO
abrir
Referência
CVE-2026-78201
itsourcecode Payroll System admin_class.php login sql injection
33RIESGO
abrir
Referência
CVE-2026-78200
itsourcecode Library Management System editbooks.php sql injection
33RIESGO
abrir
Referência
CVE-2026-78199
SourceCodester Simple Online Food Ordering System view_prod.php sql injection
33RIESGO
abrir
Referência
CVE-2026-78161
warmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds write
33RIESGO
abrir
Referência
CVE-2026-78161
warmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds write
33RIESGO
abrir
Referência
CVE-2026-78063
Tenda CH22 editFileName formeditFileName command injection
33RIESGO
abrir
Referência
CVE-2026-78060
SourceCodester Stock Management System getOrderReport.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-78122
docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
41RIESGO
abrir
Referência
CVE-2026-78049
Systerel S2OPC AddNodes Service sopc_node_mgt_helper_internal.c out-of-bounds
33RIESGO
abrir
Referência
CVE-2026-77946
TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow
48RIESGO
abrir
Referência
CVE-2026-77945
TRENDnet TEW-821DAP ssi upload.cgi command injection
33RIESGO
abrir
Referência
CVE-2026-18896
lavkush-maurya Student-Registration-System changepass.php sql injection
33RIESGO
abrir
anteriorpágina 730 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.