Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
22.832 exploits
Referência
CVE-2026-14656
code-projects Assessment Management remove-user.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-14655
code-projects Assessment Management view-users.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-15506
SecureAge CatchPulse Driver saappctl.sys heap-based overflow
41RIESGO
abrir
Referência
CVE-2026-15506
SecureAge CatchPulse Driver saappctl.sys heap-based overflow
41RIESGO
abrir
Referência
CVE-2026-15187
enquirer Public Package API Enquirer.set prototype pollution
33RIESGO
abrir
Referência
CVE-2026-15501
AstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-59807
Composio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts
41RIESGO
abrir
Referência
CVE-2026-59804
Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket
41RIESGO
abrir
Referência
CVE-2026-59803
rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol
41RIESGO
abrir
Referência
CVE-2026-15500
AstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgery
33RIESGO
abrir
Referência
CVE-2018-25367
NASA openVSP 3.16.1 Denial of Service via Buffer Overflow
33RIESGO
abrir
Referência
CVE-2018-25364
Twitter-Clone 1 SQL Injection via search.php
41RIESGO
abrir
Referência
CVE-2026-9529
GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference
33RIESGO
abrir
Referência
CVE-2026-9526
itsourcecode Electronic Judging System edit_team.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9525
itsourcecode Electronic Judging System edit_judge.php sql injection
33RIESGO
abrir
Referência
CVE-2018-17587
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RIESGO
abrir
Referência
CVE-2018-17587
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Pie Cart Pro - 'Home_Path' Remote File Inclusion
CVE-2006-4970webappsphp
PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4978webappsphp
Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arb
23RIESGO
abrir
Referência
CVE-2026-9521
fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input
33RIESGO
abrir
Referência
CVE-2026-9504
GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds
33RIESGO
abrir
Referência
CVE-2018-25363
Twitter-Clone 1 Cross-Site Request Forgery via tweetdel.php
33RIESGO
abrir
Referência
CVE-2018-25362
Twitter-Clone 1 SQL Injection via follow.php
41RIESGO
abrir
Referência
CVE-2018-25361
Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
41RIESGO
abrir
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Blue Dragon CMS 3.0.0 - Remote Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RIESGO
abrir
Referência
CVE-2026-13560
Edimax EW-7478APC POST Request formAccept os command injection
33RIESGO
abrir
Referência
CVE-2018-25360
AgataSoft Auto PingMaster 1.5 Buffer Overflow SEH
41RIESGO
abrir
Referência
CVE-2026-13558
CodeAstro Complaint Management System Report addreport cross site scripting
33RIESGO
abrir
Referência
CVE-2026-54092
File Browser: DoS Vulnerability on Public Login API
33RIESGO
abrir
anteriorpágina 748 / 762siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.