Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.301 exploits
Referência
CVE-2026-5828
code-projects Simple IT Discussion Forum addcomment.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5827
code-projects Simple IT Discussion Forum question-function.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5826
code-projects Simple IT Discussion Forum edit-category.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5705
code-projects Online Hotel Booking Booking Endpoint booknow.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5691
Totolink A7100RU cstecgi.cgi setFirewallType os command injection
33RIESGO
abrir
Referência
CVE-2026-5690
Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection
33RIESGO
abrir
Referência
CVE-2026-5689
Totolink A7100RU cstecgi.cgi setNtpCfg os command injection
33RIESGO
abrir
Referência
CVE-2026-5688
Totolink A7100RU cstecgi.cgi setDdnsCfg os command injection
33RIESGO
abrir
Referência
CVE-2026-5687
Tenda CX12L NatStaticSetting fromNatStaticSetting stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5686
Tenda CX12L RouteStatic fromRouteStatic stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5685
Tenda CX12L addressNat fromAddressNat stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5684
Tenda CX12L webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-5683
Tenda CX12L P2pListFilter fromP2pListFilter stack-based overflow
33RIESGO
abrir
Referência
CVE-2026-5682
Meesho Online Shopping App com.meesho.supply endpoint risky encryption
33RIESGO
abrir
Referência
CVE-2026-5681
itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5679
Totolink A3300R cstecgi.cgi vsetTr069Cfg os command injection
33RIESGO
abrir
Referência
CVE-2026-5678
Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection
33RIESGO
abrir
Referência
CVE-2026-5677
Totolink A7100RU cstecgi.cgi CsteSystem os command injection
33RIESGO
abrir
Referência
CVE-2026-5676
Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication
33RIESGO
abrir
Referência
CVE-2026-5675
itsourcecode Construction Management System Parameter borrowed_tool.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5672
code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection
33RIESGO
abrir
Referência
CVE-2026-5671
Cyber-III Student-Management-System Class Schedule Deletion Endpoint delete_batch.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-5670
Cyber-III Student-Management-System upload.php move_uploaded_file unrestricted upload
33RIESGO
abrir
Referência
CVE-2018-25234
SmartFTP Client 9.0.2615.0 Denial of Service via Host Field
33RIESGO
abrir
Referência
CVE-2018-25233
WebDrive 18.00.5057 Denial of Service via Secure WebDAV
33RIESGO
abrir
Referência
CVE-2018-25232
Softros LAN Messenger 9.2 Denial of Service via Log Files Location
33RIESGO
abrir
Referência
CVE-2018-25231
HeidiSQL 9.5.0.5196 Denial of Service via Preferences
33RIESGO
abrir
Referência
CVE-2018-25230
Free IP Switcher 3.1 Denial of Service via Computer Name
33RIESGO
abrir
Referência
CVE-2018-25229
BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
33RIESGO
abrir
Referência
CVE-2018-25228
NetSetMan 4.7.1 Workgroup Buffer Overflow Denial of Service
33RIESGO
abrir
anteriorpágina 446 / 744siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.