Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.066exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Referência
CVE-2026-63769
Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method
33RIESGO
abrir
Referência
CVE-2026-67201
V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
41RIESGO
abrir
Referência
CVE-2026-41939
Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
48RIESGO
abrir
Referência
CVE-2026-67217
cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
33RIESGO
abrir
Referência
CVE-2026-67216
cJSON cJSON_Compare Exponential Complexity Denial of Service
41RIESGO
abrir
Referência
CVE-2026-67215
cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
41RIESGO
abrir
Referência
CVE-2026-16492
umijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection
33RIESGO
abrir
Referência
CVE-2026-8987
Authenticated Heap Overflow
48RIESGO
abrir
Referência
CVE-2026-8986
Command Injection via Malicious OCPP Server
48RIESGO
abrir
Referência
CVE-2026-8985
Unauthenticated Command Injection
48RIESGO
abrir
Referência
CVE-2026-8984
Unauthenticated RCE
48RIESGO
abrir
Referência
CVE-2026-8983
Backdoor Authentication Token
48RIESGO
abrir
Referência
CVE-2026-63080
Aptabase SQL Injection via ClickHouse query backend
41RIESGO
abrir
Referência
CVE-2025-71408
NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments
41RIESGO
abrir
Referência
CVE-2026-65700
h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API
48RIESGO
abrir
Referência
CVE-2026-65699
AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation
28RIESGO
abrir
Referência
CVE-2014-6332
CVE-2014-6332HIGHbajo ataque
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Referência
CVE-2014-6332
CVE-2014-6332HIGHbajo ataque
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Referência
CVE-2026-63764
LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass
41RIESGO
abrir
Referência
CVE-2026-14545
TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset
48RIESGO
abrir
Referência
CVE-2026-66731
facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS
41RIESGO
abrir
Referência
CVE-2014-7169
CVE-2014-7169CRITICALbajo ataque
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Referência
CVE-2014-7169
CVE-2014-7169CRITICALbajo ataque
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Referência
CVE-2014-7169
CVE-2014-7169CRITICALbajo ataque
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Referência
CVE-2026-17433
nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization
33RIESGO
abrir
anteriorpágina 276 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.