Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.446Referência 22.166GitHub PoC 14.080VulnCheck XDB 8604Nuclei 4251Metasploit 3473✓ solo verificadosrecientespopularesriesgo
21.899 exploits
Referência
CVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RIESGO
abrir ↗Referência
CVE-2016-4316
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência
CVE-2016-4338
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef
28RIESGO
abrir ↗Referência
CVE-2016-4338
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef
28RIESGO
abrir ↗Referência
CVE-2010-1657
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers t
43RIESGO
abrir ↗Referência
CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗Referência
CVE-2010-1657
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers t
43RIESGO
abrir ↗Referência
CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir ↗Referência
CVE-2010-1658
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remo
43RIESGO
abrir ↗Referência
CVE-2010-1658
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remo
43RIESGO
abrir ↗Referência
CVE-2010-1661
Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência
CVE-2010-1681
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to ex
50RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RIESGO
abrir ↗Referência
CVE-2010-2622
SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
TorrentFlux 2.2 - 'maketorrent.php' Remote Command Execution
maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharact
23RIESGO
abrir ↗Referência✓ VexDay Proof
project alumni 1.0.9 - 'index.php?act' Local File Inclusion
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to r
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ HYIP ACME - 'news.php' SQL Injection
SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência
CVE-2026-58460
react-native-receive-sharing-intent Path Traversal via _display_name
41RIESGO
abrir ↗Referência
CVE-2026-58467
Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php
41RIESGO
abrir ↗Referência
CVE-2026-59102
Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering
28RIESGO
abrir ↗Referência
CVE-2026-59100
LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Operations
28RIESGO
abrir ↗Referência
CVE-2026-59099
Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
48RIESGO
abrir ↗Referência✓ VexDay Proof
PPA Gallery 1.0 - 'functions.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote at
23RIESGO
abrir ↗Referência
CVE-2016-4655
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir ↗Referência✓ VexDay Proof
Docebo 3.5.0.3 - 'lib.regset.php' Command Execution
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/cla
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mega File Hosting Script 1.2 - 'url' Remote File Inclusion
PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute
23RIESGO
abrir ↗Referência
CVE-2019-0552
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability."
23RIESGO
abrir ↗Referência
CVE-2014-9146
Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.