Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 14.014VulnCheck XDB 8571Nuclei 4248Metasploit 3472✓ solo verificadosrecientespopularesriesgo
21.899 exploits
Referência
CVE-2026-14719
SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management
33RIESGO
abrir ↗Referência
CVE-2026-14604
Open Asset Import Library Assimp PLY Model PlyLoader.cpp ExportToBlob double free
33RIESGO
abrir ↗Referência
CVE-2026-59098
LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search
41RIESGO
abrir ↗Referência
CVE-2026-59097
Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets
33RIESGO
abrir ↗Referência
CVE-2026-59095
LobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl
41RIESGO
abrir ↗Referência
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir ↗Referência
CVE-2026-59094
Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store
41RIESGO
abrir ↗Referência
CVE-2026-58579
RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name
33RIESGO
abrir ↗Referência
CVE-2024-58352
Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do
41RIESGO
abrir ↗Referência
CVE-2022-50973
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
48RIESGO
abrir ↗Referência
CVE-2022-50973
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
48RIESGO
abrir ↗Referência
CVE-2022-50973
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
48RIESGO
abrir ↗Referência
CVE-2026-14440
Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records
41RIESGO
abrir ↗Referência
CVE-2026-34110
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.php
48RIESGO
abrir ↗Referência✓ VexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP.NET w3wp - COM Components Remote Crash
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RIESGO
abrir ↗Referência✓ VexDay Proof
XHP CMS 0.5 - 'upload' Remote Command Execution
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea Fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBookingCalendar 1.0c - 'details_view.php' SQL Injection
SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência
CVE-2023-22518
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir ↗Referência✓ VexDay Proof
SQuery 4.5 - 'libpath' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Auton
23RIESGO
abrir ↗Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RIESGO
abrir ↗Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RIESGO
abrir ↗Referência✓ VexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, a
28RIESGO
abrir ↗Referência✓ VexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gal
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Monster Top List 1.4.2 - 'functions.php?root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sphider 1.3 - 'configset.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disa
23RIESGO
abrir ↗Referência✓ VexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.