Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
Referência
CVE-2026-14300
miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
41RIESGO
abrir
Referência
CVE-2026-14234
WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF
41RIESGO
abrir
Referência
CVE-2026-14224
Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDOR
33RIESGO
abrir
Referência
CVE-2026-13692
PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering
33RIESGO
abrir
Referência
CVE-2019-9881
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RIESGO
abrir
Referência
CVE-2019-9978
CVE-2019-9978MEDIUMbajo ataque
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
Referência
CVE-2020-0009
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This
23RIESGO
abrir
Referência
CVE-2018-25342
Smartshop 1 SQL Injection via search.php
41RIESGO
abrir
Referência
CVE-2018-25341
Smartshop 1 SQL Injection via product.php id Parameter
41RIESGO
abrir
Referência
CVE-2026-66050
NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server
41RIESGO
abrir
Referência
CVE-2026-12982
Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery
33RIESGO
abrir
Referência
CVE-2026-12497
ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection
41RIESGO
abrir
Referência
CVE-2026-16119
nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization
33RIESGO
abrir
Referência
CVE-2026-16088
halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal
33RIESGO
abrir
Referência
CVE-2026-16085
Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere
33RIESGO
abrir
Referência
CVE-2026-16084
Sipeed PicoClaw web.go web_fetch server-side request forgery
33RIESGO
abrir
Referência
CVE-2020-0618
CVE-2020-0618CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
Referência
CVE-2020-0646
CVE-2020-0646CRITICALbajo ataque
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RIESGO
abrir
Referência
CVE-2020-0674
CVE-2020-0674HIGHbajo ataque
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Referência
CVE-2020-0688
CVE-2020-0688HIGHbajo ataqueransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Referência
CVE-2020-0688
CVE-2020-0688HIGHbajo ataqueransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Referência
CVE-2026-14802
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
33RIESGO
abrir
Referência
CVE-2026-14800
imhamzaazam ecommerceFlask cross-site request forgery
33RIESGO
abrir
Referência
CVE-2026-6382
Multiple elFinder Plugins - Authenticated OS Command Injection
48RIESGO
abrir
anteriorpágina 488 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.