Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.301 exploits
Referência
CVE-2026-5828
code-projects Simple IT Discussion Forum addcomment.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5827
code-projects Simple IT Discussion Forum question-function.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5826
code-projects Simple IT Discussion Forum edit-category.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-5705
code-projects Online Hotel Booking Booking Endpoint booknow.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-5691
Totolink A7100RU cstecgi.cgi setFirewallType os command injection
33RIESGO
abrir ↗Referência
CVE-2026-5690
Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection
33RIESGO
abrir ↗Referência
CVE-2026-5687
Tenda CX12L NatStaticSetting fromNatStaticSetting stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-5684
Tenda CX12L webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-5683
Tenda CX12L P2pListFilter fromP2pListFilter stack-based overflow
33RIESGO
abrir ↗Referência
CVE-2026-5682
Meesho Online Shopping App com.meesho.supply endpoint risky encryption
33RIESGO
abrir ↗Referência
CVE-2026-5681
itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5678
Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection
33RIESGO
abrir ↗Referência
CVE-2026-5676
Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication
33RIESGO
abrir ↗Referência
CVE-2026-5675
itsourcecode Construction Management System Parameter borrowed_tool.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5672
code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5671
Cyber-III Student-Management-System Class Schedule Deletion Endpoint delete_batch.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-5670
Cyber-III Student-Management-System upload.php move_uploaded_file unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2018-25232
Softros LAN Messenger 9.2 Denial of Service via Log Files Location
33RIESGO
abrir ↗Referência
CVE-2018-25229
BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.