Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2026-15481
Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
41RIESGO
abrir
Referência
CVE-2026-15480
Trendnet TEW-635BRM Web Service rc start_httpd stack-based overflow
41RIESGO
abrir
Referência
CVE-2012-0911
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted
50RIESGO
abrir
Referência
CVE-2026-6579
liangliangyy DjangoBlog Clean Endpoint views.py missing authentication
33RIESGO
abrir
Referência
CVE-2026-6578
liangliangyy DjangoBlog Setting settings.py hard-coded credentials
33RIESGO
abrir
Referência
CVE-2026-6577
liangliangyy DjangoBlog logtracks Endpoint views.py missing authentication
33RIESGO
abrir
Referência
CVE-2026-6576
liangliangyy DjangoBlog WeChat Bot commonapi.py CommandHandler command injection
33RIESGO
abrir
Referência
CVE-2026-6573
PHPEMS Instant Exam Creation exams.master.php temppage server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-6572
Collabora KodExplorer fileUpload Endpoint share.class.php improper authorization
33RIESGO
abrir
Referência
CVE-2026-6571
kodcloud KodExplorer systemRole.class.php roleGroupAction authorization
33RIESGO
abrir
Referência
CVE-2026-6570
kodcloud KodExplorer systemMember.class.php initInstall authorization
33RIESGO
abrir
Referência
CVE-2026-6568
kodcloud KodExplorer Public Share share.class.php initShareOld path traversal
33RIESGO
abrir
Referência
CVE-2026-6125
Dromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection
33RIESGO
abrir
Referência
CVE-2018-13832
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RIESGO
abrir
Referência
CVE-2010-5056
SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to
23RIESGO
abrir
Referência
CVE-2010-5056
SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to
23RIESGO
abrir
Referência
CVE-2018-14575
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CS
23RIESGO
abrir
Referência
CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Referência
CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Referência
CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Referência
CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Referência
CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Referência
CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Referência
CVE-2026-15270
D-link DIR-823G Web boa.conf least privilege violation
41RIESGO
abrir
Referência
CVE-2026-60105
Monsta FTP < 2.14.5 SSRF via IPv4-Mapped IPv6 Address Bypass
41RIESGO
abrir
Referência
CVE-2026-10834
WP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_profile_image
33RIESGO
abrir
Referência
CVE-2018-14728
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RIESGO
abrir
Referência
CVE-2026-5655
Use After Free in Wireshark
33RIESGO
abrir
ReferênciaVexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RIESGO
abrir
Referência
CVE-2026-7686
eyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access control
33RIESGO
abrir
anteriorpágina 438 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.