Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.692 exploits
Referência
CVE-2026-6166
code-projects Vehicle Showroom Management System UpdateVehicleFunction.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-3830
Product Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQLi
41RIESGO
abrir ↗Referência
CVE-2026-6165
code-projects Vehicle Showroom Management System Login_check.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-6164
code-projects Lost and Found Thing Management addcat.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-6163
code-projects Lost and Found Thing Management catageory.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-6162
PHPGurukul Company Visitor Management System bwdates-reports-details.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-6161
code-projects Simple ChatBox Endpoint insert.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-6160
code-projects Simple ChatBox Endpoint chatbox.sql SimpleChatbox_PHP file information disclosure
33RIESGO
abrir ↗Referência
CVE-2026-6159
code-projects Simple ChatBox Endpoint insert.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2011-0404
Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows
50RIESGO
abrir ↗Referência
CVE-2011-0404
Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows
50RIESGO
abrir ↗Referência
CVE-2011-0420
The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependen
28RIESGO
abrir ↗Referência
CVE-2013-0632
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RIESGO
abrir ↗Referência
CVE-2021-4473
Tianxin Internet Behavior Management System Command Injection via toQuery.php
48RIESGO
abrir ↗Referência
CVE-2026-22666
Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()
46RIESGO
abrir ↗Referência
CVE-2026-1900
Link Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update
33RIESGO
abrir ↗Referência
CVE-2025-15611
Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF
33RIESGO
abrir ↗Referência✓ VexDay Proof
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject
23RIESGO
abrir ↗Referência
CVE-2026-5719
itsourcecode Construction Management System borrowedtool.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5692
Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection
33RIESGO
abrir ↗Referência
CVE-2013-0722
Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow loc
23RIESGO
abrir ↗Referência
CVE-2013-0742
Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial
35RIESGO
abrir ↗Referência
CVE-2013-0803
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RIESGO
abrir ↗Referência
CVE-2013-0803
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RIESGO
abrir ↗Referência
CVE-2011-0489
The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows rem
28RIESGO
abrir ↗Referência
CVE-2013-0928
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote
50RIESGO
abrir ↗Referência
CVE-2013-1306
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a cr
35RIESGO
abrir ↗Referência
CVE-2026-5574
Technostrobe HI-LED-WR120-G2 FsBrowseClean deletefile authorization
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.