Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.446Referência 22.166GitHub PoC 14.080VulnCheck XDB 8604Nuclei 4251Metasploit 3473✓ solo verificadosrecientespopularesriesgo
21.899 exploits
Referência
CVE-2026-9414
SourceCodester Indian Invoicing System Invoice Template Render Database-Backed add_order.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-9413
SourceCodester Indian Invoicing System category.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-9412
SourceCodester Indian Invoicing System Backend Endpoint access control
33RIESGO
abrir ↗Referência
CVE-2026-9411
SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9410
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-9405
Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-9401
Edimax BR-6675nD POST Request formWanTcpipSetup buffer overflow
41RIESGO
abrir ↗Referência✓ VexDay Proof
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kjtechforce mailman b1 - Delete Row 'code' SQL Injection
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
VisoHotlink 1.01 - 'functions.visohotlink.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPSherpa - '/include/config.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
webSPELL 4.01.02 - 'gallery.php' Blind SQL Injection
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpXD 0.3 - 'path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sami HTTP Server 2.0.1 - HTTP 404 Object not found Denial of Service
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RIESGO
abrir ↗Referência✓ VexDay Proof
RPW 1.0.2 - 'config.php?sql_language' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗Referência
CVE-2009-2363
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls
23RIESGO
abrir ↗Referência
CVE-2009-2363
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls
23RIESGO
abrir ↗Referência
CVE-2009-2385
SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 fo
23RIESGO
abrir ↗Referência
CVE-2009-2392
SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute ar
23RIESGO
abrir ↗Referência
CVE-2009-2400
SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência
CVE-2009-2402
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Remotesoft .NET Explorer 2.0.1 - Local Stack Overflow (PoC)
Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of
23RIESGO
abrir ↗Referência
CVE-2022-29303
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RIESGO
abrir ↗Referência✓ VexDay Proof
Flip 2.01 final - 'previewtheme.php?inc_path' Remote File Inclusion
PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote
35RIESGO
abrir ↗Referência✓ VexDay Proof
Photo Galerie Standard 1.1 - 'view.php' SQL Injection
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Poll 2.0.5-dev - Remote Admin Session Generator
admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain admin
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.