Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
21.534 exploits
Referência
CVE-2026-6621
1024bit extend-deep index.js prototype pollution
33RIESGO
abrir
Referência
CVE-2010-5026
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
exV2 < 2.0.4.3 - 'extract()' Remote Command Execution
CVE-2006-7080webappsphp
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to de
23RIESGO
abrir
ReferênciaVexDay Proof
PhpNews 1.0 - 'Include' Remote File Inclusion
CVE-2006-7081webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir
Referência
CVE-2026-6799
Comfast CF-N1-S Endpoint mbox-config command injection
33RIESGO
abrir
Referência
CVE-2026-6745
Bagisto Custom Scripts cross site scripting
33RIESGO
abrir
Referência
CVE-2026-41456
Bludit CMS Reflected XSS via Search Plugin
33RIESGO
abrir
Referência
CVE-2026-6744
Bagisto Downloadable Link copy server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-6743
WebSystems WebTOTUM Calendar cross site scripting
33RIESGO
abrir
Referência
CVE-2019-25714
Seeyon Office Anywhere (OA) A8 Unauthenticated Arbitrary File Write via htmlofficeservlet
48RIESGO
abrir
Referência
CVE-2019-25714
Seeyon Office Anywhere (OA) A8 Unauthenticated Arbitrary File Write via htmlofficeservlet
48RIESGO
abrir
Referência
CVE-2026-6662
ericc-ch copilot-api Token Endpoint server.ts cors cross-domain policy
33RIESGO
abrir
Referência
CVE-2026-6652
Pagekit CMS StringStorage Template PhpEngine.php evaluate eval injection
33RIESGO
abrir
Referência
CVE-2026-6651
erponline.xyz ERP Online Inventory Edit Item cross site scripting
33RIESGO
abrir
Referência
CVE-2026-6650
Z-BlogPHP ZBA File app_upload.php UnPack unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-34429
Vvveb < 1.0.8.1 Stored XSS via Media Upload and Rename
33RIESGO
abrir
Referência
CVE-2026-6649
Qibo CMS headers server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-6648
Qibo CMS Internal Message cross site scripting
33RIESGO
abrir
Referência
CVE-2026-6636
p2r3 convert API buildCache.js Bun.serve path traversal
33RIESGO
abrir
Referência
CVE-2026-6635
rowboatlabs rowboat tools_webhook app.py tool_call improper authentication
33RIESGO
abrir
Referência
CVE-2026-6634
usememos UpdateInstanceSetting App.tsx memos_access_token improper authorization
33RIESGO
abrir
Referência
CVE-2026-6633
Yifang CMS Extended Management L_rbac_admin.php store cross site scripting
33RIESGO
abrir
Referência
CVE-2026-6632
Tenda F451 httpd SafeClientFilter fromSafeClientFilter buffer overflow
41RIESGO
abrir
Referência
CVE-2026-6631
Tenda F451 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow
41RIESGO
abrir
Referência
CVE-2026-6630
Tenda F451 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow
41RIESGO
abrir
Referência
CVE-2026-6629
Metasoft 美特软件 MetaCRM Interface sql.jsp Statement.executeUpdate sql injection
33RIESGO
abrir
Referência
CVE-2026-6628
phili67 Ecclesia CRM Query Viewer view ValidateInput sql injection
33RIESGO
abrir
Referência
CVE-2026-6626
Cockpit-HQ Cockpit Asset Handler/Aggregate data query logic injection
33RIESGO
abrir
Referência
CVE-2026-6625
moxi624 Mogu Blog v2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadPictureByUrl server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-6624
BichitroGan ISP Billing Software Pool List add cross site scripting
33RIESGO
abrir
anteriorpágina 190 / 718siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.