Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.587exploits catalogados
35.644CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.428GitHub PoC 14.268VulnCheck XDB 8663Nuclei 4299Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.407 exploits
Referência
CVE-2026-15193
AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
33RIESGO
abrir ↗Referência
CVE-2026-15184
GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
33RIESGO
abrir ↗Referência
CVE-2026-14798
CodeAstro Apartment Visitor Management System visitor-entry.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-66746
Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
33RIESGO
abrir ↗Referência
CVE-2023-47268
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RIESGO
abrir ↗Referência
CVE-2024-46508
yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting
41RIESGO
abrir ↗Referência
CVE-2026-13694
Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass
33RIESGO
abrir ↗Referência
CVE-2026-13693
Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal
33RIESGO
abrir ↗Referência
CVE-2020-20277
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver
28RIESGO
abrir ↗Referência
CVE-2020-2038
PAN-OS: OS command injection vulnerability in the management web interface
78RIESGO
abrir ↗Referência
CVE-2020-2096
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref
60RIESGO
abrir ↗Referência
b2evolution 6.11.6 - 'plugin name' Stored XSS
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution
23RIESGO
abrir ↗Referência
CVE-2020-23522
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
23RIESGO
abrir ↗Referência
Tailor MS 1.0 - Reflected Cross-Site Scripting
A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Mana
33RIESGO
abrir ↗Referência
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa
28RIESGO
abrir ↗Referência✓ VexDay Proof
RiteCMS 2.2.1 - Authenticated Remote Code Execution
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php
28RIESGO
abrir ↗Referência
CVE-2020-23972
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating
50RIESGO
abrir ↗Referência
CVE-2026-16627
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RIESGO
abrir ↗Referência
CVE-2026-17008
Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN
33RIESGO
abrir ↗Referência
CVE-2026-16990
Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation
33RIESGO
abrir ↗Referência
CVE-2026-16747
Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions
33RIESGO
abrir ↗Referência
CVE-2026-16621
Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler
33RIESGO
abrir ↗Referência
CVE-2026-15213
Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback
33RIESGO
abrir ↗Referência
CVE-2026-15045
Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount
33RIESGO
abrir ↗Referência
CVE-2026-19217
Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget
33RIESGO
abrir ↗Referência
CVE-2026-19073
Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.