Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8663Nuclei 4287Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.407 exploits
Referência
CVE-2026-19353
DedeCMS Installation Wizard index.php _4_Setup file inclusion
28RIESGO
abrir ↗Referência
CVE-2019-1346
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RIESGO
abrir ↗Referência
CVE-2019-13494
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long var
23RIESGO
abrir ↗Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RIESGO
abrir ↗Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RIESGO
abrir ↗Referência
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in
28RIESGO
abrir ↗Referência
CVE-2026-9428
Tenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2018-25350
userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
48RIESGO
abrir ↗Referência
CVE-2026-9306
QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization
33RIESGO
abrir ↗Referência
CVE-2026-9305
QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9304
calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery
28RIESGO
abrir ↗Referência
CVE-2026-17044
WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid
41RIESGO
abrir ↗Referência
CVE-2026-14767
CodeAstro Ecommerce Website POST Parameter confirm.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14766
CodeAstro Apartment Visitor Management System POST Parameter search-result.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14764
code-projects Hotel and Tourism Reservation Event Management add_event.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14763
code-projects Hotel and Tourism Reservation Tour Reservations tour_reserves.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14762
code-projects Hotel and Tourism Reservation Room Management rooms.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-17014
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips
33RIESGO
abrir ↗Referência
CVE-2026-16992
Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication
33RIESGO
abrir ↗Referência
CVE-2026-16988
GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint
41RIESGO
abrir ↗Referência✓ VexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl
23RIESGO
abrir ↗Referência
CVE-2019-14750
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w
43RIESGO
abrir ↗Referência✓ VexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w
43RIESGO
abrir ↗Referência
CVE-2019-15081
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing fe
23RIESGO
abrir ↗Referência
MaxxAudio Drivers WavesSysSvc64.exe 1.6.2.0 - Local Privilege Escalation
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result,
23RIESGO
abrir ↗Referência
ManageEngine Application Manager 14.2 - Privilege Escalation / Remote Command Execution (Metasploit)
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in
23RIESGO
abrir ↗Referência
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.