Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
21.534 exploits
Referência
CVE-2026-6118
AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection
48RIESGO
abrir ↗Referência
CVE-2012-0981
Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image fil
43RIESGO
abrir ↗Referência
CVE-2019-0543
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft W
71RIESGO
abrir ↗Referência✓ VexDay Proof
Virtual CD 9.0.0.2 - 'vc9api.DLL' Remote Shell Commands Execution
The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência
CVE-2018-5725
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of t
23RIESGO
abrir ↗Referência
CVE-2018-5725
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Achievo 1.3.2 - 'FCKeditor' Arbitrary File Upload
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/co
23RIESGO
abrir ↗Referência✓ VexDay Proof
Electronics Workbench - '.ewb' Local Stack Overflow (PoC)
Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a deni
23RIESGO
abrir ↗Referência
CVE-2017-2473
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RIESGO
abrir ↗Referência
CVE-2020-26829
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary conne
48RIESGO
abrir ↗Referência
CVE-2013-1937
Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might
23RIESGO
abrir ↗Referência
CVE-2010-1305
Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly ot
43RIESGO
abrir ↗Referência
CVE-2019-10226
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to th
23RIESGO
abrir ↗Referência
CVE-2019-10226
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to th
23RIESGO
abrir ↗Referência
CVE-2011-4024
Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers t
23RIESGO
abrir ↗Referência
CVE-2018-6671
SB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerability
33RIESGO
abrir ↗Referência
CVE-2013-3639
Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbi
23RIESGO
abrir ↗Referência
CVE-2014-3220
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary u
28RIESGO
abrir ↗Referência
CVE-2021-24405
Easy Cookie Policy <= 1.6.2 - Broken Access Control to Stored Cross-Site Scripting
28RIESGO
abrir ↗Referência
CVE-2014-125117
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RIESGO
abrir ↗Referência
CVE-2014-125117
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RIESGO
abrir ↗Referência
CVE-2014-125117
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RIESGO
abrir ↗Referência
CVE-2025-7097
Comodo Internet Security Premium Manifest File cis_update_x64.xml os command injection
48RIESGO
abrir ↗Referência
CVE-2025-7097
Comodo Internet Security Premium Manifest File cis_update_x64.xml os command injection
48RIESGO
abrir ↗Referência
CVE-2018-12052
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
23RIESGO
abrir ↗Referência
CVE-2024-23749
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RIESGO
abrir ↗Referência✓ VexDay Proof
Web Content System 2.7.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content Syste
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 'FFI' Extension 5.0.5 - 'Safe_mode' Local Bypass
The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context
23RIESGO
abrir ↗Referência✓ VexDay Proof
eFront 3.5.1 / build 2710 - Arbitrary File Upload
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Adobe JRun 4 - 'logfile' (Authenticated) Directory Traversal
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.