Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 14.014VulnCheck XDB 8571Nuclei 4248Metasploit 3472✓ solo verificadosrecientespopularesriesgo
21.899 exploits
Referência✓ VexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Blue Dragon CMS 3.0.0 - Remote Code Execution
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RIESGO
abrir ↗Referência✓ VexDay Proof
ZoomStats 1.0.2 - 'mysql.php' Remote File Inclusion
PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is
23RIESGO
abrir ↗Referência
CVE-2009-4598
SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
BrudaGB 1.1 - '/admin/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RIESGO
abrir ↗Referência✓ VexDay Proof
BrudaNews 1.1 - '/admin/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RIESGO
abrir ↗Referência✓ VexDay Proof
N/X WCMS 4.1 - 'nxheader.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Manageme
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RIESGO
abrir ↗Referência
CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗Referência
CVE-2026-10157
Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication
33RIESGO
abrir ↗Referência
CVE-2026-10156
Open5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption
33RIESGO
abrir ↗Referência
CVE-2026-10155
Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injection
33RIESGO
abrir ↗Referência
CVE-2026-10153
westboy CicadasCMS AbstractCacheManager.java search cross site scripting
33RIESGO
abrir ↗Referência
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Referência
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Referência✓ VexDay Proof
Techno Dreams Guestbook 1.0 - 'key' SQL Injection
SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência
CVE-2009-4624
SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Techno Dreams Announcement - 'key' SQL Injection
SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência
CVE-2020-8515
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RIESGO
abrir ↗Referência
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Referência
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Referência
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Referência✓ VexDay Proof
Evince Document Viewer - 'DocumentMedia' Remote Buffer Overflow
Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows u
28RIESGO
abrir ↗Referência✓ VexDay Proof
PHPManta 1.0.2 - 'view-sourcecode.php' Local File Inclusion
Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPPortal 4.0.0 - 'default1.asp' SQL Injection
SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
NuSchool 1.0 - 'CampusNewsDetails.asp' SQL Injection
SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
USupport 1.0 - 'detail.asp' SQL Injection
SQL injection vulnerability in detail.asp in Superfreaker Studios USupport 1.0 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
AspPired2Poll 1.0 - 'MoreInfo.asp' SQL Injection
SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.