Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.797 exploits
Referência
CVE-2016-6664
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server befo
23RIESGO
abrir ↗Referência
CVE-2020-7991
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
23RIESGO
abrir ↗Referência
CVE-2020-7991
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
23RIESGO
abrir ↗Referência
CVE-2021-21466
SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow
48RIESGO
abrir ↗Referência
CVE-2009-4234
Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910
23RIESGO
abrir ↗Referência✓ VexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read
23RIESGO
abrir ↗Referência✓ VexDay Proof
ExBB 0.22 - Local/Remote File Inclusion
ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to cre
23RIESGO
abrir ↗Referência
CVE-2017-6367
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology invo
23RIESGO
abrir ↗Referência
CVE-2010-1876
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência
CVE-2012-2277
The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote
23RIESGO
abrir ↗Referência
CVE-2021-30044
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
23RIESGO
abrir ↗Referência
CVE-2010-1876
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência
CVE-2017-9602
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-man
23RIESGO
abrir ↗Referência
CVE-2026-10082
Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter
33RIESGO
abrir ↗Referência
CVE-2012-5876
Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to c
23RIESGO
abrir ↗Referência
CVE-2016-5740
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RIESGO
abrir ↗Referência
CVE-2016-5740
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RIESGO
abrir ↗Referência
CVE-2011-4558
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Referência
CVE-2017-8684
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R
23RIESGO
abrir ↗Referência
CVE-2017-17110
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
23RIESGO
abrir ↗Referência
CVE-2018-8411
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vuln
23RIESGO
abrir ↗Referência
CVE-2009-2890
Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arb
23RIESGO
abrir ↗Referência
CVE-2018-7701
Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers
23RIESGO
abrir ↗Referência
CVE-2026-65709
sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API
41RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Import Tools Mod 0.1.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chicken of the VNC 2.0 - 'NULL-pointer' Remote Denial of Service
Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large compu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flat Chat 2.0 - 'include online.txt' Remote Code Execution
Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
STPHPLibrary - 'STPHPLIB_DIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.