Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.301 exploits
Referência
CVE-2026-7065
BidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-7064
AgentDeskAI browser-tools-mcp browser-connector.ts os command injection
33RIESGO
abrir
Referência
CVE-2026-7063
code-projects Employee Management System Endpoint eprocess.php sql injection
33RIESGO
abrir
Referência
CVE-2026-7062
Intina47 context-sync Git Integration git-integration.ts os command injection
33RIESGO
abrir
Referência
CVE-2026-7061
Toowiredd chatgpt-mcp-server MCP/HTTP docker.service.ts os command injection
33RIESGO
abrir
Referência
CVE-2026-7059
666ghj MiroFish Query Parameter simulation.py get_simulation_posts path traversal
33RIESGO
abrir
Referência
CVE-2026-7058
666ghj MiroFish Inter-Process Communication simulation_ipc.py SimulationIPCClient.send_command command injection
33RIESGO
abrir
Referência
CVE-2026-7057
Tenda F456 httpd setcfm buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7056
Tenda F456 httpd SafeUrlFilter fromSafeUrlFilter buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7055
Tenda F456 httpd VirtualSer fromVirtualSer buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7054
Tenda F456 httpd PPTPDClient fromPptpUserAdd buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7053
Tenda F456 httpd L7Prot frmL7ProtForm buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7044
GreenCMS index.php themeadd unrestricted upload
33RIESGO
abrir
Referência
CVE-2017-7180
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its
23RIESGO
abrir
Referência
CVE-2017-7228
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The e
23RIESGO
abrir
Referência
CVE-2017-7269
CVE-2017-7269CRITICALbajo ataque
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
Referência
CVE-2017-7269
CVE-2017-7269CRITICALbajo ataque
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
Referência
CVE-2026-6492
arnobt78 Hotel Booking Management System Health Check Endpoint detailed information disclosure
33RIESGO
abrir
Referência
CVE-2026-6491
libvips nip2 vips7compat.c im_minpos_vec heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-6490
QueryMine sms GET Request Parameter deletecourse.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6489
QueryMine sms Background Management addteacher.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-6488
QueryMine sms GET Request Parameter editcourse.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6487
Qihui jtbc5 CMS Code Endpoint manage.php path traversal
33RIESGO
abrir
Referência
CVE-2026-6486
classroombookings User Display Name layout.php read cross site scripting
33RIESGO
abrir
Referência
CVE-2026-6483
Wavlink WL-WN530H4 internet.cgi snprintf os command injection
46RIESGO
abrir
Referência
CVE-2026-6148
code-projects Vehicle Showroom Management System MonthTotalReportUpdateFunction.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6140
Totolink A7100RU CGI cstecgi.cgi UploadFirmwareFile os command injection
48RIESGO
abrir
Referência
CVE-2026-6139
Totolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection
48RIESGO
abrir
Referência
CVE-2026-6138
Totolink A7100RU CGI cstecgi.cgi setAccessDeviceCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-6129
zhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication
33RIESGO
abrir
anteriorpágina 443 / 744siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.