Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.692 exploits
Referência
CVE-2026-17459
perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
33RIESGO
abrir ↗Referência
CVE-2018-4404
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improve
61RIESGO
abrir ↗Referência
CVE-2026-17458
mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-17457
mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure
33RIESGO
abrir ↗Referência
CVE-2026-65010
Datasets Symlink-following Arbitrary File Write via Extractor.extract()
33RIESGO
abrir ↗Referência
CVE-2026-63765
Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
41RIESGO
abrir ↗Referência
CVE-2018-5702
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con
28RIESGO
abrir ↗Referência
CVE-2026-38764
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
41RIESGO
abrir ↗Referência
CVE-2026-16628
oclif JIT Plugin Entry child_process.exec os command injection
33RIESGO
abrir ↗Referência
CVE-2026-65013
Onlook tRPC Insecure Direct Object Reference via multiple procedures
41RIESGO
abrir ↗Referência
CVE-2026-12968
Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload
41RIESGO
abrir ↗Referência
CVE-2026-16490
itsourcecode Hospital Management System prescription.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-16451
zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2026-64824
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
48RIESGO
abrir ↗Referência
CVE-2026-16450
zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization
33RIESGO
abrir ↗Referência
CVE-2026-16449
zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection
33RIESGO
abrir ↗Referência
CVE-2026-16448
D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
33RIESGO
abrir ↗Referência
CVE-2026-63770
Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
41RIESGO
abrir ↗Referência
CVE-2026-63771
Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
33RIESGO
abrir ↗Referência
CVE-2026-15535
AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserialization
33RIESGO
abrir ↗Referência
CVE-2026-15481
Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
41RIESGO
abrir ↗Referência
CVE-2026-15480
Trendnet TEW-635BRM Web Service rc start_httpd stack-based overflow
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.