Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2026-3176
Missing Authorization in GitLab
28RIESGO
abrir
Referência
CVE-2026-5309
Authorization Bypass Through User-Controlled Key in GitLab
33RIESGO
abrir
Referência
CVE-2026-10749
Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData
41RIESGO
abrir
Referência
CVE-2026-10735
ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
41RIESGO
abrir
Referência
CVE-2026-10531
AI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortcode Attribute
33RIESGO
abrir
Referência
CVE-2026-56115
Bootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass
41RIESGO
abrir
Referência
CVE-2026-56109
ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c
41RIESGO
abrir
Referência
CVE-2026-6858
Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS
41RIESGO
abrir
Referência
CVE-2026-4259
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions
41RIESGO
abrir
Referência
CVE-2026-4110
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
33RIESGO
abrir
Referência
CVE-2026-10530
Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
33RIESGO
abrir
Referência
CVE-2026-13592
liftoff-sr CIPster EtherNet IP Message append out-of-bounds write
33RIESGO
abrir
Referência
CVE-2026-13591
DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
28RIESGO
abrir
Referência
CVE-2026-13590
seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-13589
seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-34112
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
48RIESGO
abrir
Referência
CVE-2026-13588
seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-13587
seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-13583
Edimax EW-7478APC POST Request formUSBFolder buffer overflow
41RIESGO
abrir
Referência
CVE-2016-20084
WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS
33RIESGO
abrir
Referência
CVE-2016-20083
WordPress More Fields Plugin 2.1 Cross-Site Request Forgery
33RIESGO
abrir
Referência
CVE-2016-20082
WordPress Plugin Abtest Local File Inclusion via abtest_admin.php
33RIESGO
abrir
Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
OllyDbg 1.10 - Local Format String
CVE-2004-0733localwindows
Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly ex
23RIESGO
abrir
Referência
CVE-2026-12797
BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
33RIESGO
abrir
Referência
CVE-2026-12776
Montodel House-Rental-Management index.php houses sql injection
33RIESGO
abrir
Referência
CVE-2026-12774
BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-12771
BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
28RIESGO
abrir
Referência
CVE-2022-50972
WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
48RIESGO
abrir
Referência
CVE-2018-8279
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
45RIESGO
abrir
anteriorpágina 473 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.