Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.459 exploits
Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTSchedulerService_
20RIESGO
abrir ↗Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir ↗Exploit-DB
Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
Microsoft Outlook Remote Code Execution Vulnerability
41RIESGO
abrir ↗Exploit-DB
Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
33RIESGO
abrir ↗Exploit-DB
Lost and Found Information System v1.0 - SQL Injection
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RIESGO
abrir ↗Exploit-DB
WP AutoComplete 1.0.4 - Unauthenticated SQLi
WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
48RIESGO
abrir ↗Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
Microsoft Excel Remote Code Execution Vulnerability
41RIESGO
abrir ↗Exploit-DB
POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p
23RIESGO
abrir ↗Exploit-DB
TP-Link TL-WR940N V4 - Buffer OverFlow
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg
35RIESGO
abrir ↗Exploit-DB
FuguHub 8.1 - Remote Code Execution
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RIESGO
abrir ↗Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
Microsoft Office Remote Code Execution Vulnerability
41RIESGO
abrir ↗Exploit-DB
Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RIESGO
abrir ↗Exploit-DB
Windows 11 22h2 - Kernel Privilege Elevation
Windows Kernel Elevation of Privilege Vulnerability
41RIESGO
abrir ↗Exploit-DB
PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download
41RIESGO
abrir ↗Exploit-DB
Azure Apache Ambari 2302250400 - Spoofing
Azure Apache Ambari Spoofing Vulnerability
33RIESGO
abrir ↗Exploit-DB
Microsoft SharePoint Enterprise Server 2016 - Spoofing
Microsoft SharePoint Server Spoofing Vulnerability
41RIESGO
abrir ↗Exploit-DB
NCH Express Invoice - Clear Text Password Storage and Account Takeover
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
23RIESGO
abrir ↗Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RIESGO
abrir ↗Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RIESGO
abrir ↗Exploit-DB
WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Super Socializer 7.13.52 - Reflected XSS
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir ↗Exploit-DB
WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
Password reset links invalidation issue in WordPress
38RIESGO
abrir ↗Exploit-DB
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
Code Injection in pyload/pyload
85RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sales Tracker Management System v1.0 - Multiple Vulnerabilities
SourceCodester Sales Tracker Management System cross site scripting
28RIESGO
abrir ↗Exploit-DB
Teachers Record Management System 1.0 - File Upload Type Validation
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
33RIESGO
abrir ↗Exploit-DB
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.