Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.937VulnCheck XDB 8510Nuclei 4239Metasploit 3468✓ solo verificadosrecientespopularesriesgo
21.797 exploits
Referência
CVE-2026-67298
FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow
41RIESGO
abrir ↗Referência
CVE-2023-39026
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
43RIESGO
abrir ↗Referência
CVE-2020-6756
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re
53RIESGO
abrir ↗Referência
CVE-2026-14840
YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing
23RIESGO
abrir ↗Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir ↗Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir ↗Referência
CVE-2026-14839
Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure
41RIESGO
abrir ↗Referência
CVE-2026-14823
Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR
23RIESGO
abrir ↗Referência
CVE-2026-14822
Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
23RIESGO
abrir ↗Referência
CVE-2026-14561
Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure
33RIESGO
abrir ↗Referência✓ VexDay Proof
D-Bus Daemon < 1.2.4 - 'libdbus' Denial of Service
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a deni
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ionFiles 4.4.2 - File Disclosure
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remo
43RIESGO
abrir ↗Referência
CVE-2026-14315
Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission
33RIESGO
abrir ↗Referência
CVE-2026-14292
WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
33RIESGO
abrir ↗Referência
CVE-2014-5201
SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2014-9224
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management serve
23RIESGO
abrir ↗Referência
CVE-2010-1352
Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote
43RIESGO
abrir ↗Referência
CVE-2010-0288
A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12
28RIESGO
abrir ↗Referência
CVE-2010-1353
Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to re
43RIESGO
abrir ↗Referência
CVE-2010-1354
Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers t
43RIESGO
abrir ↗Referência
CVE-2020-23839
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa
28RIESGO
abrir ↗Referência
CVE-2020-35754
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl
28RIESGO
abrir ↗Referência
CVE-2012-4768
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attac
43RIESGO
abrir ↗Referência
CVE-2016-6754
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-
23RIESGO
abrir ↗Referência
CVE-2012-3996
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (
23RIESGO
abrir ↗Referência
CVE-2012-3996
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / disable_functions Bypass
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_funct
23RIESGO
abrir ↗Referência✓ VexDay Proof
BulletProof FTP Client - '.bps' Local Stack Overflow (PoC)
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bp
23RIESGO
abrir ↗Referência
CVE-2019-19363
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.