Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.692 exploits
Referência
CVE-2026-5988
Tenda F451 AdvSetWrlsafeset formWrlsafeset stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-5987
Sanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engine
33RIESGO
abrir ↗Referência
CVE-2026-5985
code-projects Simple IT Discussion Forum crud.php sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
phpEventCalendar 0.2.3 - 'eventdisplay.php' SQL Injection
SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência
CVE-2026-5585
Tencent AI-Infra-Guard Task Detail Endpoint task_manager.go information disclosure
33RIESGO
abrir ↗Referência
CVE-2026-5584
Fosowl agenticSeek query Endpoint PyInterpreter.py PyInterpreter.execute code injection
33RIESGO
abrir ↗Referência
CVE-2026-5583
PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5580
CodeAstro Online Classroom Parameter addvideos.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5579
CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5578
CodeAstro Online Classroom Parameter addassessment.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5577
Song-Li cross_browser details Endpoint uniquemachine_app.py sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5576
SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2026-5575
SourceCodester/jkev Record Management System Login index.php sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
JW Player - 'playerready' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers
23RIESGO
abrir ↗Referência
CVE-2026-5453
Rico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded key
33RIESGO
abrir ↗Referência
CVE-2026-5452
UCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key
33RIESGO
abrir ↗Referência
CVE-2026-5420
Shinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded key
28RIESGO
abrir ↗Referência
CVE-2026-5417
Dataease SQLbot Elasticsearch es_engine.py get_es_data_by_http server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-5370
krayin laravel-crm Activities Module/Notes inbox.spec.ts composeMail cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-5368
projectworlds Car Rental Project Parameter login.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5354
Trendnet TEW-657BRM setup.cgi vpn_connect os command injection
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.