Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.692 exploits
Referência
CVE-2026-13512
Databend Tenant client_session_manager.rs state_key authorization
33RIESGO
abrir ↗Referência
CVE-2026-13511
VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization
28RIESGO
abrir ↗Referência
CVE-2026-13509
RAGapp Knowledge File files.py FileHandler.remove_file path traversal
33RIESGO
abrir ↗Referência
CVE-2026-13504
code-projects Project Management System Mail Compose mail.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-13500
antlr ANTLR4 Grammar Action Block OutputFile.java code injection
33RIESGO
abrir ↗Referência
CVE-2020-13951
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
45RIESGO
abrir ↗Referência
CVE-2020-14008
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in
35RIESGO
abrir ↗Referência
CVE-2020-14166
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RIESGO
abrir ↗Referência
CVE-2020-14181
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RIESGO
abrir ↗Referência
CVE-2026-57518
Pagekit CMS 1.0.18 Privilege Escalation via UserApiController
41RIESGO
abrir ↗Referência
CVE-2026-36908
A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8
33RIESGO
abrir ↗Referência
CVE-2026-10753
Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update
28RIESGO
abrir ↗Referência
CVE-2020-14882
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗Referência
CVE-2026-11497
D-Link DCS-5615 Boa Webserver boa.conf least privilege violation
33RIESGO
abrir ↗Referência
CVE-2026-11491
CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-11489
code-projects Online Music Site AdminDeleteAlbum.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11488
code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injection
33RIESGO
abrir ↗Referência
CVE-2020-14944
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can all
23RIESGO
abrir ↗Referência
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir ↗Referência
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir ↗Referência
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir ↗Referência
CVE-2020-17456
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa
60RIESGO
abrir ↗Referência
Seowon SLR-120 Router - Remote Code Execution (Unauthenticated)
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa
60RIESGO
abrir ↗Referência
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗Referência
CVE-2026-10124
Shibby Tomato Zserv ripd rip_zebra_read_ipv4 stack-based overflow
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.