Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.528exploits catalogados
35.606CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2026-9350
NousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorization
33RIESGO
abrir
Referência
CVE-2026-9349
calcom cal.diy Generic React API bookings-single-view.getServerSideProps.tsx getServerSideProps information disclosure
33RIESGO
abrir
Referência
CVE-2018-25358
D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi
41RIESGO
abrir
Referência
CVE-2018-25356
SIPp 3.6 Local Buffer Overflow via Command-line Arguments
41RIESGO
abrir
Referência
CVE-2018-25355
Audiograbber 1.83 Local Buffer Overflow via SEH
41RIESGO
abrir
Referência
CVE-2018-25353
Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File Upload
41RIESGO
abrir
Referência
CVE-2018-25352
WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_id
41RIESGO
abrir
Referência
CVE-2018-25344
10-Strike Network Inventory Explorer 8.54 Buffer Overflow SEH
41RIESGO
abrir
Referência
CVE-2018-25343
Smartshop 1 Cross-Site Request Forgery via editprofile.php
33RIESGO
abrir
Referência
CVE-2026-15519
usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted control sphere
28RIESGO
abrir
Referência
CVE-2026-15194
Open5GS AMF context.c amf_context_final use after free
33RIESGO
abrir
Referência
CVE-2026-15192
mettle sendportal APIv1 Webhooks mailjet missing authentication
33RIESGO
abrir
Referência
CVE-2026-15191
mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization
33RIESGO
abrir
Referência
CVE-2026-11827
Insufficiently Protected Credentials in GitLab
33RIESGO
abrir
Referência
CVE-2026-13320
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RIESGO
abrir
Referência
CVE-2026-59806
Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint
33RIESGO
abrir
Referência
CVE-2026-60104
Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request
48RIESGO
abrir
Referência
CVE-2026-15036
Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization
33RIESGO
abrir
Referência
CVE-2026-15035
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
33RIESGO
abrir
Referência
CVE-2026-15034
flask-dashboard Flask-MonitoringDashboard cross-site request forgery
33RIESGO
abrir
Referência
CVE-2019-11510
CVE-2019-11510CRITICALbajo ataqueransomware
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Referência
CVE-2019-11510
CVE-2019-11510CRITICALbajo ataqueransomware
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Referência
CVE-2021-47977
WordPress Anti-Malware Security Bruteforce Firewall <= 4.20.72 Directory Traversal
41RIESGO
abrir
Referência
CVE-2019-11539
CVE-2019-11539HIGHbajo ataqueransomware
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
Referência
CVE-2026-8786
Tencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseForInitialization authorization
33RIESGO
abrir
Referência
CVE-2026-8784
npitre cramfs-tools cramfsck.c change_file_status symlink
33RIESGO
abrir
Referência
CVE-2026-8783
omec-project amf dispatcher.go UERadioCapabilityCheckResponse null pointer dereference
33RIESGO
abrir
Referência
CVE-2026-8781
omec-project amf handler.go RANConfiguration null pointer dereference
33RIESGO
abrir
Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RIESGO
abrir
Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RIESGO
abrir
anteriorpágina 480 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.