Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2026-4512
WP reCaptcha by WebDesignBy < 2.0 – Admin+ Stored XSS
28RIESGO
abrir
Referência
CVE-2026-4106
HT Mega < 3.0.7 – Unauthenticated PII Disclosure
48RIESGO
abrir
Referência
CVE-2026-6878
ByteDance verl grader.py math_equal sandbox
33RIESGO
abrir
Referência
CVE-2026-6874
ericc-ch copilot-api Header token dns rebinding
33RIESGO
abrir
Referência
CVE-2026-40517
radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names
41RIESGO
abrir
Referência
CVE-2026-34413
Xerte Online Toolkits Missing Authentication via connector.php
56RIESGO
abrir
Referência
CVE-2026-34415
Xerte Online Toolkits File Upload RCE via elfinder Connector
63RIESGO
abrir
ReferênciaVexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
CVE-2008-6861webappsphp
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
CVE-2008-6862webappsphp
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Live Support 5.1 - Insecure Cookie Handling
CVE-2008-6864webappsphp
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative a
23RIESGO
abrir
ReferênciaVexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6870webappsasp
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information
23RIESGO
abrir
ReferênciaVexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6871webappsasp
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Active Web Mail 4 - Blind SQL Injection
CVE-2008-6873webappsasp
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the Tab
23RIESGO
abrir
ReferênciaVexDay Proof
ASPSiteWare Automotive Dealer 1.0/2.0 - SQL Injection
CVE-2008-6874webappsphp
Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2010-4721
SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2017-9810
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Mai
23RIESGO
abrir
Referência
CVE-2017-9810
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Mai
23RIESGO
abrir
Referência
CVE-2017-9822
CVE-2017-9822HIGHbajo ataqueransomware
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RIESGO
abrir
Referência
CVE-2026-7214
eghuzefa engineer-your-data server.py file_inf path traversal
33RIESGO
abrir
Referência
CVE-2026-7213
ef10007 MLOps_MCP save_file Tool fastmcp_server.py path traversal
33RIESGO
abrir
Referência
CVE-2026-7212
edvardlindelof notes-mcp notes_mcp.py path traversal
33RIESGO
abrir
Referência
CVE-2026-7211
dvladimirov MCP Git Search API mcp_server.py GitSearchRequest command injection
33RIESGO
abrir
Referência
CVE-2026-7206
dubydu sqlite-mcp entry.py extract_to_json sql injection
33RIESGO
abrir
Referência
CVE-2026-7205
duartium papers-mcp-server main.py search_papers path traversal
33RIESGO
abrir
Referência
CVE-2026-7204
Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-7203
Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection
48RIESGO
abrir
Referência
CVE-2026-38651
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw
41RIESGO
abrir
Referência
CVE-2026-7202
Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection
48RIESGO
abrir
Referência
CVE-2026-7146
AlejandroArciniegas mcp-data-vis HTTP Request server.js axios server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-7143
1000 Projects Portfolio Management System MCA block_status.php sql injection
33RIESGO
abrir
anteriorpágina 431 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.