Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.429GitHub PoC 14.270VulnCheck XDB 8693Nuclei 4299Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.429 exploits
Referência
CVE-2020-28978
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a
28RIESGO
abrir ↗Referência✓ VexDay Proof
WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allo
23RIESGO
abrir ↗Referência
OpenCart 3.0.3.6 - 'Profile Image' Stored Cross-Site Scripting (Authenticated)
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as
23RIESGO
abrir ↗Referência
CVE-2020-3161
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
100RIESGO
abrir ↗Referência
CVE-2026-14756
code-projects Hotel and Tourism Reservation Tour Management add_tour.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14755
code-projects Hotel and Tourism Reservation Reservations Management reservations.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14754
code-projects Hotel and Tourism Reservation add_room.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14744
code-projects Real State Services normalHomeRent.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14742
langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
28RIESGO
abrir ↗Referência
CVE-2026-13517
Tenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-10820
ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR
41RIESGO
abrir ↗Referência
CVE-2016-20086
Vembu StoreGrid 4.0 Unquoted Service Path Privilege Escalation
41RIESGO
abrir ↗Referência
CVE-2016-20085
Realtek High Definition Audio Driver 6.0.1.6730 Privilege Escalation
41RIESGO
abrir ↗Referência
PHP-Fusion CMS 9.03.90 - Cross-Site Request Forgery (Delete admin shoutbox message)
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker
23RIESGO
abrir ↗Referência
Newgen Correspondence Management System (corms) eGov 12.0 - IDOR
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information
28RIESGO
abrir ↗Referência
CVE-2020-35948
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta
53RIESGO
abrir ↗Referência
CVE-2026-73506
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
33RIESGO
abrir ↗Referência
CVE-2026-18046
Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update
33RIESGO
abrir ↗Referência
CVE-2026-18035
User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API
33RIESGO
abrir ↗Referência
CVE-2026-16977
Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name
41RIESGO
abrir ↗Referência
CVE-2026-16737
WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart
33RIESGO
abrir ↗Referência
CVE-2026-16538
TeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up
48RIESGO
abrir ↗Referência
CVE-2026-16294
Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL
41RIESGO
abrir ↗Referência
CVE-2026-16253
Total Upkeep (BoldGrid Backup) < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret (regression of CVE-2020-36848)
41RIESGO
abrir ↗Referência
CVE-2026-16066
Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name
33RIESGO
abrir ↗Referência
CVE-2026-16051
WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action
48RIESGO
abrir ↗Referência
CVE-2026-15388
Cookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure
33RIESGO
abrir ↗Referência
CVE-2026-15249
Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.