Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
23.022 exploits
Referência
CVE-2026-19897
mangroup dtale Login Endpoint auth.py login excessive authentication
33RIESGO
abrir ↗Referência
CVE-2026-19896
mangroup dtale Flask Session Cookie app.py build_secret_key random values
33RIESGO
abrir ↗Referência
CVE-2026-19895
opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive authentication
33RIESGO
abrir ↗Referência
CVE-2019-13494
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long var
23RIESGO
abrir ↗Referência
CVE-2026-7732
code-projects BloodBank Managing System request_blood.php unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RIESGO
abrir ↗Referência
CVE-2026-18216
Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
33RIESGO
abrir ↗Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RIESGO
abrir ↗Referência
CVE-2026-16611
Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
41RIESGO
abrir ↗Referência
CVE-2026-16541
Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints
33RIESGO
abrir ↗Referência
CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir ↗Referência
CVE-2025-61884
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RIESGO
abrir ↗Referência
CVE-2026-19834
Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization
33RIESGO
abrir ↗Referência
CVE-2026-19829
648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal
33RIESGO
abrir ↗Referência
CVE-2021-3378
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RIESGO
abrir ↗Referência
CVE-2021-3378
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RIESGO
abrir ↗Referência
CVE-2026-19828
648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal
33RIESGO
abrir ↗Referência
CVE-2026-19827
alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal
33RIESGO
abrir ↗Referência
CVE-2026-19826
alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization
33RIESGO
abrir ↗Referência✓ VexDay Proof
BIND 9.4.1 < 9.4.2 - Remote DNS Cache Poisoning (Metasploit)
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir ↗Referência
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in
28RIESGO
abrir ↗Referência
CVE-2023-0904
SourceCodester Employee Task Management System task-details.php sql injection
33RIESGO
abrir ↗Referência
CVE-2008-5970
SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to exe
23RIESGO
abrir ↗Referência★ 47
Unauthenticated RCE on CraftCMS when PHP `register_argc_argv` config setting is enabled
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir ↗Referência
CVE-2016-7288
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RIESGO
abrir ↗Referência✓ VexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir ↗Referência✓ VexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.