Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.618exploits catalogados
35.646CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.429GitHub PoC 14.268VulnCheck XDB 8693Nuclei 4299Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.407 exploits
Referência
CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir ↗Referência
CVE-2019-5526
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by t
23RIESGO
abrir ↗Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir ↗Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir ↗Referência
CVE-2019-6249
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/inde
23RIESGO
abrir ↗Referência
CVE-2019-6279
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnera
23RIESGO
abrir ↗Referência
CVE-2026-15501
AstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-15500
AstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-59807
Composio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts
41RIESGO
abrir ↗Referência
CVE-2026-59804
Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket
41RIESGO
abrir ↗Referência
CVE-2026-59803
rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol
41RIESGO
abrir ↗Referência
CVE-2019-6279
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnera
23RIESGO
abrir ↗Referência
CVE-2019-6282
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag
23RIESGO
abrir ↗Referência
CVE-2026-34102
Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info_get.php
48RIESGO
abrir ↗Referência
CVE-2026-58454
JAIOTlink C492A-W6 4.8.30.57701411 RCE via /Anyka/config Endpoint
41RIESGO
abrir ↗Referência
CVE-2026-13560
Edimax EW-7478APC POST Request formAccept os command injection
33RIESGO
abrir ↗Referência
CVE-2026-13558
CodeAstro Complaint Management System Report addreport cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-13557
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-13556
itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-13555
itsourcecode Online Hotel Management System controller.php add sql injection
33RIESGO
abrir ↗Referência
CVE-2026-53264
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RIESGO
abrir ↗Referência
Coship Wireless Router 4.0.0.48 / 4.0.0.40 / 5.0.0.54 / 5.0.0.55 / 10.0.0.49 - Unauthenticated Admin Password Reset
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM33
35RIESGO
abrir ↗Referência
CVE-2026-9529
GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference
33RIESGO
abrir ↗Referência
CVE-2026-9526
itsourcecode Electronic Judging System edit_team.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9525
itsourcecode Electronic Judging System edit_judge.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9521
fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.