Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.624 exploits
Referência
CVE-2026-14650
connorskees grass UTF-8 Character raw_to_parse_error denial of service
33RIESGO
abrir ↗Referência
CVE-2026-14648
code-projects Online Voting System Login authentication.php test_input sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14647
onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
33RIESGO
abrir ↗Referência
CVE-2026-14642
SourceCodester Class and Exam Timetabling System edit_class2.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14628
NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
33RIESGO
abrir ↗Referência
CVE-2026-14627
NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication
33RIESGO
abrir ↗Referência
CVE-2026-14626
NousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of service
33RIESGO
abrir ↗Referência
CVE-2026-14625
NousResearch hermes-agent server.py shell.exec protection mechanism
33RIESGO
abrir ↗Referência
CVE-2026-11880
Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
28RIESGO
abrir ↗Referência
CVE-2026-11794
Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
41RIESGO
abrir ↗Referência
CVE-2026-11562
WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
33RIESGO
abrir ↗Referência
CVE-2026-10750
Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
41RIESGO
abrir ↗Referência
CVE-2025-15666
Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2026-58172
Ocelot - IP Allow/Block List Bypass for WebSocket Upgrade Requests
48RIESGO
abrir ↗Referência
CVE-2026-58166
OpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and Delete
41RIESGO
abrir ↗Referência
CVE-2026-58116
LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
48RIESGO
abrir ↗Referência
CVE-2026-13545
D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
41RIESGO
abrir ↗Referência
CVE-2026-13541
itsourcecode Hospital Management System doctorchangepassword.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-13531
itsourcecode Hospital Management System department.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-13530
itsourcecode Hospital Management System Appointment appointmentdetail.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-13528
YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal
33RIESGO
abrir ↗Referência
CVE-2026-13515
Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.