Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 14.014VulnCheck XDB 8571Nuclei 4248Metasploit 3472✓ solo verificadosrecientespopularesriesgo
21.899 exploits
Referência
CVE-2026-12796
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
33RIESGO
abrir ↗Referência
CVE-2026-12795
BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
33RIESGO
abrir ↗Referência
CVE-2026-12788
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
33RIESGO
abrir ↗Referência
CVE-2026-12786
Ezbsystems UltraISO Premium Edition Kernel Driver bootpt64.sys access control
41RIESGO
abrir ↗Referência
CVE-2026-12781
EaseUS Partition Master Kernel Driver epmntdrv.sys access control
41RIESGO
abrir ↗Referência
CVE-2026-12776
Montodel House-Rental-Management index.php houses sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
openmovieeditor 0.0.20060901 - 'name' Local Buffer Overflow
Buffer overflow in Open Movie Editor 0.0.20060901 allows local users to cause a denial of service (system crash) or exec
23RIESGO
abrir ↗Referência
CVE-2009-4578
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
TualBLOG 1.0 - 'icerikno' SQL Injection
Multiple SQL injection vulnerabilities in icerik.asp in TualBLOG 1.0 allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência
CVE-2026-12183
Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
48RIESGO
abrir ↗Referência
CVE-2026-9062
Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal
28RIESGO
abrir ↗Referência
CVE-2026-12066
PbootCMS Password MemberController.php retrieve password recovery
33RIESGO
abrir ↗Referência
CVE-2026-12065
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
28RIESGO
abrir ↗Referência
CVE-2026-12065
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
28RIESGO
abrir ↗Referência
CVE-2026-8589
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RIESGO
abrir ↗Referência
CVE-2026-20253
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RIESGO
abrir ↗Referência
CVE-2026-25860
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RIESGO
abrir ↗Referência
CVE-2026-25860 POC git
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RIESGO
abrir ↗Referência
CVE-2026-34417
OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php
33RIESGO
abrir ↗Referência
CVE-2017-20250
WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download
41RIESGO
abrir ↗Referência
CVE-2025-55651
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows
33RIESGO
abrir ↗Referência
CVE-2026-11582
CodeAstro Student Attendance Management System index.php sql injection
33RIESGO
abrir ↗Referência
CVE-2021-22005
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir ↗Referência
CVE-2017-8484
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RIESGO
abrir ↗Referência
CVE-2020-5902
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir ↗Referência
CVE-2026-10616
nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTasksTool.executeComplete authorization
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.