Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8663Nuclei 4287Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.407 exploits
Referência
CVE-2026-14300
miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
41RIESGO
abrir ↗Referência
CVE-2026-14234
WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF
41RIESGO
abrir ↗Referência
CVE-2026-14224
Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDOR
33RIESGO
abrir ↗Referência
CVE-2019-9881
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RIESGO
abrir ↗Referência
CVE-2019-9978
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir ↗Referência
CVE-2020-0009
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This
23RIESGO
abrir ↗Referência
CVE-2026-66050
NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server
41RIESGO
abrir ↗Referência
CVE-2026-12982
Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery
33RIESGO
abrir ↗Referência
CVE-2026-12497
ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection
41RIESGO
abrir ↗Referência
CVE-2026-16119
nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization
33RIESGO
abrir ↗Referência
CVE-2026-16088
halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal
33RIESGO
abrir ↗Referência
CVE-2026-16085
Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere
33RIESGO
abrir ↗Referência
CVE-2020-0618
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir ↗Referência
CVE-2020-0646
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RIESGO
abrir ↗Referência
CVE-2020-0674
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir ↗Referência
CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗Referência
CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2026-14802
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
33RIESGO
abrir ↗Referência
CVE-2026-6382
Multiple elFinder Plugins - Authenticated OS Command Injection
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.