Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
Referência
CVE-2026-4110
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
33RIESGO
abrir
Referência
CVE-2026-10530
Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
33RIESGO
abrir
Referência
CVE-2026-13592
liftoff-sr CIPster EtherNet IP Message append out-of-bounds write
33RIESGO
abrir
Referência
CVE-2026-13591
DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
28RIESGO
abrir
Referência
CVE-2026-13590
seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-13589
seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-34112
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
48RIESGO
abrir
Referência
CVE-2026-13588
seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-13587
seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
33RIESGO
abrir
Referência
CVE-2026-13583
Edimax EW-7478APC POST Request formUSBFolder buffer overflow
41RIESGO
abrir
Referência
CVE-2018-8065
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RIESGO
abrir
Referência
CVE-2026-11623
tmux image.c image_free use after free
28RIESGO
abrir
Referência
CVE-2026-11555
D-Link DGS-1100-08PD Web boa.conf least privilege violation
33RIESGO
abrir
Referência
CVE-2026-11553
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-11516
UTT HiPER 2610G formNatStaticMap strcpy buffer overflow
33RIESGO
abrir
Referência
CVE-2026-11514
itsourcecode Hospital Management System addpatient.php sql injection
33RIESGO
abrir
Referência
CVE-2026-11513
itsourcecode Hospital Management System adminaccount.php sql injection
33RIESGO
abrir
Referência
CVE-2026-11508
CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection
33RIESGO
abrir
Referência
CVE-2026-8089
weMail < 2.1.3 - Reflected Cross-Site Scripting
41RIESGO
abrir
Referência
CVE-2026-55706
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values f
33RIESGO
abrir
Referência
CVE-2016-20081
WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download
41RIESGO
abrir
Referência
CVE-2016-20073
Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php
41RIESGO
abrir
Referência
CVE-2017-20262
Joomla! Component Ajax Quiz 1.8 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20257
Joomla! Component Quiz Deluxe 3.7.4 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20256
Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
41RIESGO
abrir
Referência
CVE-2017-20255
Joomla! Component JB Visa 1.0 SQL Injection via visatype
41RIESGO
abrir
Referência
CVE-2017-20254
Joomla! Component User Bench 1.0 SQL Injection via userid
41RIESGO
abrir
Referência
CVE-2017-20253
Joomla! Component My Projects 2.0 SQL Injection
41RIESGO
abrir
Referência
CVE-2017-20252
Joomla NextGen Editor 2.1.0 SQL Injection via plname Parameter
41RIESGO
abrir
Referência
CVE-2023-54353
Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
anteriorpágina 487 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.