Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8663Nuclei 4287Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.407 exploits
Referência
CVE-2026-4110
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
33RIESGO
abrir ↗Referência
CVE-2026-10530
Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
33RIESGO
abrir ↗Referência
CVE-2026-13592
liftoff-sr CIPster EtherNet IP Message append out-of-bounds write
33RIESGO
abrir ↗Referência
CVE-2026-13591
DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
28RIESGO
abrir ↗Referência
CVE-2026-13590
seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2026-13589
seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2026-34112
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
48RIESGO
abrir ↗Referência
CVE-2026-13588
seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2026-13587
seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2018-8065
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RIESGO
abrir ↗Referência
CVE-2026-11514
itsourcecode Hospital Management System addpatient.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11513
itsourcecode Hospital Management System adminaccount.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11508
CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-55706
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values f
33RIESGO
abrir ↗Referência
CVE-2016-20081
WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download
41RIESGO
abrir ↗Referência
CVE-2016-20073
Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php
41RIESGO
abrir ↗Referência
CVE-2017-20256
Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
41RIESGO
abrir ↗Referência
CVE-2017-20252
Joomla NextGen Editor 2.1.0 SQL Injection via plname Parameter
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.