Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.692 exploits
Referência✓ VexDay Proof
@lex Guestbook 4.0.2 - Remote Command Execution
Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to cre
23RIESGO
abrir ↗Referência✓ VexDay Proof
uniForum 4 - 'wbsearch.aspx' SQL Injection
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Core 2.0.6 - 'wp-trackback.php' SQL Injection
wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric
28RIESGO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX 10.4.8 - AppleTalk 'ATPsndrsp()' Heap Buffer Overflow (PoC)
Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remot
28RIESGO
abrir ↗Referência✓ VexDay Proof
sNews 1.5.30 - Remote Reset Admin Pass / Command Execution
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mint Haber Sistemi 2.7 - 'duyuru.asp?id' SQL Injection
SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Article System 0.1 - 'INCLUDE_DIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with
23RIESGO
abrir ↗Referência
CVE-2022-41040
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Referência
CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗Referência
CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Help Workshop 4.03.0002 - '.cnt' Local Buffer Overflow
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitr
35RIESGO
abrir ↗Referência
CVE-2009-4781
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
CCRP Folder Treeview Control (ccrpftv6.ocx) - IE Denial of Service
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attacke
28RIESGO
abrir ↗Referência
CVE-2009-4783
Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Oreon 1.2.3 RC4 - '/lang/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência
CVE-2009-4784
SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
BrowseDialog Class 'ccrpbds6.dll' Internet Explorer 7 - Denial of Service
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RIESGO
abrir ↗Referência
CVE-2020-10189
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RIESGO
abrir ↗Referência✓ VexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (2)
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RIESGO
abrir ↗Referência
CVE-2026-7290
JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
33RIESGO
abrir ↗Referência
CVE-2022-35405
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code
100RIESGO
abrir ↗Referência✓ VexDay Proof
DivX Player 6.4.1 - DivXBrowserPlugin 'npdivx32.dll' IE Denial of Service
DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2009-4785
SQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute a
23RIESGO
abrir ↗Referência
CVE-2026-7283
SourceCodester Pharmacy Sales and Inventory System ajax.php save_expired sql injection
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.