Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
Referência
CVE-2019-8928
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userMan
23RIESGO
abrir
Referência
CVE-2019-9082
CVE-2019-9082HIGHbajo ataque
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RIESGO
abrir
Referência
CVE-2026-42626
HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD
33RIESGO
abrir
Referência
CVE-2026-4929
Simple Hierarchical Select (Drupal 7) XSS in term-derived output
33RIESGO
abrir
Referência
CVE-2026-47102
LiteLLM < 1.83.10 Privilege Escalation via User Update
41RIESGO
abrir
Referência
CVE-2026-47102
LiteLLM < 1.83.10 Privilege Escalation via User Update
41RIESGO
abrir
Referência
CVE-2026-47101
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
41RIESGO
abrir
Referência
CVE-2026-47101
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
41RIESGO
abrir
Referência
CVE-2026-47101
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
41RIESGO
abrir
Referência
CVE-2019-9162
In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient
23RIESGO
abrir
Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RIESGO
abrir
Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RIESGO
abrir
Referência
CVE-2019-9491
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RIESGO
abrir
ReferênciaVexDay Proof
Millewin 13.39.146.1 - Local Privilege Escalation
CVE-2021-3394localwindows
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
23RIESGO
abrir
Referência
CVE-2026-9450
code-projects Employee Management System psubmit.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9449
code-projects Employee Management System changepassemp.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9448
code-projects Employee Management System applyleave.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-9447
SourceCodester Simple POS and Inventory System search.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9446
SourceCodester Simple POS and Inventory System edit_customer.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9445
SourceCodester Simple POS and Inventory System File Extension addproduct.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-9444
SourceCodester Simple POS and Inventory System GET Parameter deleteproduct.php delete sql injection
33RIESGO
abrir
Referência
CVE-2026-9443
Edimax BR-6478AC POST Request formL2TPSetup buffer overflow
41RIESGO
abrir
Referência
CVE-2026-9441
Edimax BR-6478AC POST Request formiNICbasic command injection
33RIESGO
abrir
Referência
CVE-2026-9437
DTStack Taier REST API Runtime.exec os command injection
33RIESGO
abrir
Referência
CVE-2026-67349
OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
41RIESGO
abrir
Referência
CVE-2026-67348
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
41RIESGO
abrir
Referência
CVE-2026-67347
Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update
33RIESGO
abrir
Referência
CVE-2026-67345
MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
41RIESGO
abrir
Referência
CVE-2026-14310
Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
33RIESGO
abrir
Referência
CVE-2026-14305
WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes
33RIESGO
abrir
anteriorpágina 498 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.